CVE Feed

    Dashboard / CVE / CVE-2021-25217

    CVE-2021-25217

    In ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16, ISC DHCP 4.4.0 -> 4.4.2 (Other branches of ISC DHCP (i.e., releases in the 4.0.x series or lower and releases in the 4.3.x series) are beyond their End-of-Life (EOL) and no longer supported by ISC. From inspection it is clear that the defect is also present in releases from those series, but they have not been officially tested for the vulnerability), The outcome of encountering the defect while reading a lease that will trigger it varies, according to: the component being affected (i.e., dhclient or dhcpd) whether the package was built as a 32-bit or 64-bit binary whether the compiler flag -fstack-protection-strong was used when compiling In dhclient, ISC has not successfully reproduced the error on a 64-bit system. However, on a 32-bit system it is possible to cause dhclient to crash when reading an improper lease, which could cause network connectivity problems for an affected system due to the absence of a running DHCP client process. In dhcpd, when run in DHCPv4 or DHCPv6 mode: if the dhcpd server binary was built for a 32-bit architecture AND the -fstack-protection-strong flag was specified to the compiler, dhcpd may exit while parsing a lease file containing an objectionable lease, resulting in lack of service to clients. Additionally, the offending lease and the lease immediately following it in the lease database may be improperly deleted. if the dhcpd server binary was built for a 64-bit architecture OR if the -fstack-protection-strong compiler flag was NOT specified, the crash will not occur, but it is possible for the offending lease and the lease which immediately followed it to be improperly deleted.

    Published:May 26, 2021
    Last Modified:Nov 21, 2024
    EPS:May 26, 2021
    EPSS Score:0.00304
    CVSS Score:7.4

    Affected Products

    Vendor
    Debian
    Product
    Debian Linux
    Vendor
    Fedoraproject
    Product
    Fedora
    Vendor
    Isc
    Product
    Dhcp
    Vendor
    Netapp
    Product
    Ontap Select Deploy Administration Utility
    Vendor
    Netapp
    Product
    Solidfire \& Hci Management Node
    Vendor
    Redhat
    Product
    Enterprise Linux
    Vendor
    Redhat
    Product
    Openshift
    Vendor
    Redhat
    Product
    Rhel Aus
    Vendor
    Redhat
    Product
    Rhel E4s
    Vendor
    Redhat
    Product
    Rhel Els
    Vendor
    Redhat
    Product
    Rhel Eus
    Vendor
    Redhat
    Product
    Rhel Tus
    Vendor
    Siemens
    Product
    Ruggedcom Rox Mx5000
    Vendor
    Siemens
    Product
    Ruggedcom Rox Mx5000 Firmware
    Vendor
    Siemens
    Product
    Ruggedcom Rox Rx1400
    Vendor
    Siemens
    Product
    Ruggedcom Rox Rx1400 Firmware
    Vendor
    Siemens
    Product
    Ruggedcom Rox Rx1500
    Vendor
    Siemens
    Product
    Ruggedcom Rox Rx1500 Firmware
    Vendor
    Siemens
    Product
    Ruggedcom Rox Rx1501
    Vendor
    Siemens
    Product
    Ruggedcom Rox Rx1501 Firmware
    Vendor
    Siemens
    Product
    Ruggedcom Rox Rx1510
    Vendor
    Siemens
    Product
    Ruggedcom Rox Rx1510 Firmware
    Vendor
    Siemens
    Product
    Ruggedcom Rox Rx1511
    Vendor
    Siemens
    Product
    Ruggedcom Rox Rx1511 Firmware
    Vendor
    Siemens
    Product
    Ruggedcom Rox Rx1512
    Vendor
    Siemens
    Product
    Ruggedcom Rox Rx1512 Firmware
    Vendor
    Siemens
    Product
    Ruggedcom Rox Rx1524
    Vendor
    Siemens
    Product
    Ruggedcom Rox Rx1524 Firmware
    Vendor
    Siemens
    Product
    Ruggedcom Rox Rx1536
    Vendor
    Siemens
    Product
    Ruggedcom Rox Rx1536 Firmware
    Vendor
    Siemens
    Product
    Ruggedcom Rox Rx5000
    Vendor
    Siemens
    Product
    Ruggedcom Rox Rx5000 Firmware
    Vendor
    Siemens
    Product
    Sinec Ins

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High