SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-29921

This (in some situations) allows attackers to bypass access control that is based on IP addresses.

CRITICAL 9.8EPSS 6.88%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (6.88%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
6.88% probability · 94th percentile
CISA KEV
Not listed
Affected
python/python · oracle/communications cloud native core automated test suite · oracle/communications cloud native core binding support function · oracle/communications cloud native core network slice selection function · oracle/graalvm · oracle/zfs storage appliance kit
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.