Remote Code Execution Risk in Busybox's Hush Applet
CVE-2021-42377

9.8CRITICAL

Key Information:

Vendor

Busybox

Status
Vendor
CVE Published:
15 November 2021

What is CVE-2021-42377?

A vulnerability in the hush applet of Busybox can lead to denial of service and potential remote code execution through manipulated shell commands. The mishandling of the special '&&&' string by the shell creates an opportunity for attackers to exploit this weakness, especially in scenarios where input commands are filtered. This flaw could have significant security implications if exploited under the right conditions.

Affected Version(s)

busybox < 1.34.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.