5
CVSSv2

CVE-2021-28683

Published: 20/05/2021 Updated: 27/05/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in Envoy up to and including 1.71.1. There is a remotely exploitable NULL pointer dereference and crash in TLS when an unknown TLS alert code is received.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

envoyproxy envoy 1.16.2

envoyproxy envoy 1.17.1

Vendor Advisories

A NULL pointer dereference vulnerability was found envoyproxy/envoy This flaw allows an attacker to establish a TLS session that sends an invalid TLS alert code, causing a NULL pointer exception to occur that crashes the application, resulting in a denial of service The highest threat from this vulnerability is to system availability ...
Envoy before version 1180, and subsequently Istio before version 193, contains a remotely exploitable NULL pointer dereference and crash in TLS when an unknown TLS alert code is received ...