Out-of-Bounds Read in Squid's WCCP Protocol Allows Information Disclosure
CVE-2021-28116
3.7LOW
What is CVE-2021-28116?
In some configurations of Squid Proxy Server versions up to 5.0.5, an out-of-bounds read vulnerability in the WCCP protocol can lead to information disclosure. This flaw can potentially be exploited in combination with other vulnerabilities to achieve remote code execution. It is crucial for organizations using Squid to address this issue promptly to safeguard their systems against possible attacks.
References
EPSS Score
10% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved