CVE-2021-29662
 
Severity Score
7.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
3
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.
El módulo Data::Validate::IP versiones hasta 0.29 para Perl, no considera apropiadamente los caracteres cero extraños al comienzo de una cadena de dirección IP, lo que (en algunas situaciones) permite a los atacantes omitir el control de acceso que se basa en direcciones IP.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2021-03-31 CVE Reserved
- 2021-03-31 CVE Published
- 2024-03-06 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-704: Incorrect Type Conversion or Cast
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://github.com/houseabsolute/Data-Validate-IP | Product | |
https://security.netapp.com/advisory/ntap-20210604-0002 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://blog.urth.org/2021/03/29/security-issues-in-perl-ip-address-distros | 2024-08-03 | |
https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-018.md | 2024-08-03 | |
https://sick.codes/sick-2021-018 | 2024-08-03 |
URL | Date | SRC |
---|---|---|
https://github.com/houseabsolute/Data-Validate-IP/commit/3bba13c819d616514a75e089badd75002fd4f14e | 2023-08-08 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Data::validate::ip Project Search vendor "Data::validate::ip Project" | Data::validate::ip Search vendor "Data::validate::ip Project" for product "Data::validate::ip" | <= 0.29 Search vendor "Data::validate::ip Project" for product "Data::validate::ip" and version " <= 0.29" | perl |
Affected
| ||||||
Netapp Search vendor "Netapp" | Snapcenter Search vendor "Netapp" for product "Snapcenter" | - | - |
Affected
|