SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-30129

A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error.

MEDIUM 6.5EPSS 3.05%

Does this matter?

Lower severity and a low EPSS score (3.05%). Track it; it rarely justifies an emergency change on its own.

Description

A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
3.05% probability · 87th percentile
CISA KEV
Not listed
Weakness
CWE-772
Affected
apache/sshd · oracle/banking payments · oracle/banking trade finance · oracle/banking treasury management · oracle/communications cloud native core console · oracle/flexcube universal banking · oracle/middleware common libraries and tools · oracle/oss support tools · oracle/retail customer management and segmentation foundation
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.