// For flags

CVE-2021-21783

 

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.

Se presenta una vulnerabilidad de ejecución de código en la funcionalidad del plugin WS-Addressing de Genivia gSOAP versión 2.8.107. Una petición SOAP especialmente diseñada puede conllevar a una ejecución de código remota. Un atacante puede enviar una petición HTTP para desencadenar esta vulnerabilidad

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-01-04 CVE Reserved
  • 2021-03-25 CVE Published
  • 2024-07-28 EPSS Updated
  • 2024-08-03 CVE Updated
  • 2024-08-03 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-190: Integer Overflow or Wraparound
  • CWE-680: Integer Overflow to Buffer Overflow
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Genivia
Search vendor "Genivia"
Gsoap
Search vendor "Genivia" for product "Gsoap"
2.8.107
Search vendor "Genivia" for product "Gsoap" and version "2.8.107"
-
Affected
Oracle
Search vendor "Oracle"
Communications Diameter Signaling Router
Search vendor "Oracle" for product "Communications Diameter Signaling Router"
>= 8.0.0 <= 8.5.0
Search vendor "Oracle" for product "Communications Diameter Signaling Router" and version " >= 8.0.0 <= 8.5.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Eagle Application Processor
Search vendor "Oracle" for product "Communications Eagle Application Processor"
>= 16.1.0 <= 16.4.0
Search vendor "Oracle" for product "Communications Eagle Application Processor" and version " >= 16.1.0 <= 16.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Eagle Lnp Application Processor
Search vendor "Oracle" for product "Communications Eagle Lnp Application Processor"
46.7
Search vendor "Oracle" for product "Communications Eagle Lnp Application Processor" and version "46.7"
-
Affected
Oracle
Search vendor "Oracle"
Communications Eagle Lnp Application Processor
Search vendor "Oracle" for product "Communications Eagle Lnp Application Processor"
46.8
Search vendor "Oracle" for product "Communications Eagle Lnp Application Processor" and version "46.8"
-
Affected
Oracle
Search vendor "Oracle"
Communications Eagle Lnp Application Processor
Search vendor "Oracle" for product "Communications Eagle Lnp Application Processor"
46.9
Search vendor "Oracle" for product "Communications Eagle Lnp Application Processor" and version "46.9"
-
Affected
Oracle
Search vendor "Oracle"
Communications Lsms
Search vendor "Oracle" for product "Communications Lsms"
13.1
Search vendor "Oracle" for product "Communications Lsms" and version "13.1"
-
Affected
Oracle
Search vendor "Oracle"
Communications Lsms
Search vendor "Oracle" for product "Communications Lsms"
13.2
Search vendor "Oracle" for product "Communications Lsms" and version "13.2"
-
Affected
Oracle
Search vendor "Oracle"
Communications Lsms
Search vendor "Oracle" for product "Communications Lsms"
13.3
Search vendor "Oracle" for product "Communications Lsms" and version "13.3"
-
Affected
Oracle
Search vendor "Oracle"
Communications Lsms
Search vendor "Oracle" for product "Communications Lsms"
13.4
Search vendor "Oracle" for product "Communications Lsms" and version "13.4"
-
Affected
Oracle
Search vendor "Oracle"
Tekelec Virtual Operating Environment
Search vendor "Oracle" for product "Tekelec Virtual Operating Environment"
>= 3.4.0 <= 3.7.1
Search vendor "Oracle" for product "Tekelec Virtual Operating Environment" and version " >= 3.4.0 <= 3.7.1"
-
Affected