6.8
CVSSv2

CVE-2021-42377

Published: 15/11/2021 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare conditions of filtered command input.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

busybox busybox 1.33.1

busybox busybox 1.33.0

fedoraproject fedora 33

fedoraproject fedora 34

netapp cloud backup -

netapp solidfire -

netapp hci management node -

netapp h300s_firmware -

netapp h500s_firmware -

netapp h700s_firmware -

netapp h300e_firmware -

netapp h500e_firmware -

netapp h700e_firmware -

netapp h410s_firmware -

Vendor Advisories

An attacker-controlled pointer free in Busybox's hush applet before version 1340 leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string This may be used for remote code execution under rare conditions of filtered command input ...