7.5
CVSSv3

CVE-2021-28682

Published: 20/05/2021 Updated: 27/05/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in Envoy up to and including 1.71.1. There is a remotely exploitable integer overflow in which a very large grpc-timeout value leads to unexpected timeout calculations.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

envoyproxy envoy 1.14.6

envoyproxy envoy 1.15.3

envoyproxy envoy 1.16.2

envoyproxy envoy 1.17.1

Vendor Advisories

A flaw was found in envoyproxy/envoy An attacker, able to craft a packet which specifies a large grpc-timeout, can potentially cause envoy to incorrectly calculate the timeouts resulting in a denial of service The highest threat from this vulnerability is to system availability ...
Envoy before version 1180, and subsequently Istio before version 193, contains a remotely exploitable integer overflow in which a very large grpc-timeout value leads to unexpected timeout calculations ...