Denial of Service Vulnerability in Squid by Squid Software Foundation
CVE-2021-33620

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
28 May 2021

What is CVE-2021-33620?

The vulnerability allows remote servers to induce a denial of service in Squid by sending an HTTP response that includes an expected header. This can lead to service disruptions for all clients using the affected versions of Squid. Attackers do not have to utilize malicious intent; simply sending a valid HTTP response can trigger the issue, making it a significant concern for users reliant on Squid for caching and proxy services.

References

EPSS Score

8% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.