CVE-2021-27565
The web server in InterNiche NicheStack through 4.0.1 allows remote attackers to cause a denial of service (infinite loop and networking outage) via an unexpected valid HTTP request such as OPTIONS.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.59%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The web server in InterNiche NicheStack through 4.0.1 allows remote attackers to cause a denial of service (infinite loop and networking outage) via an unexpected valid HTTP request such as OPTIONS. This occurs because the HTTP request handler enters a miscoded wbs_loop() debugger hook.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.59% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-835
- Affected
- hcc-embedded/nichestack
- Source
- cve@mitre.org
References
- https://www.forescout.com/blog/new-critical-operational-technology-vulnerabilities-found-on-nichestack/Mitigation, Third Party Advisory
- https://www.hcc-embedded.com/Product
- https://www.hcc-embedded.com/about/about-internicheProduct
- https://www.kb.cert.org/vuls/id/608209Third Party Advisory, US Government Resource
- https://www.forescout.com/blog/new-critical-operational-technology-vulnerabilities-found-on-nichestack/Mitigation, Third Party Advisory
- https://www.hcc-embedded.com/Product
- https://www.hcc-embedded.com/about/about-internicheProduct
- https://www.kb.cert.org/vuls/id/608209Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.