Executive Summary

Informations
Name CVE-2021-45098 First vendor Publication 2021-12-16
Vendor Cve Last vendor Modification 2022-01-04

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Overall CVSS Score 7.5
Base Score 7.5 Environmental Score 7.5
impact SubScore 3.6 Temporal Score 7.5
Exploitabality Sub Score 3.9
 
Attack Vector Network Attack Complexity Low
Privileges Required None User Interaction None
Scope Unchanged Confidentiality Impact None
Integrity Impact High Availability Impact None
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:P/A:N)
Cvss Base Score 5 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

An issue was discovered in Suricata before 6.0.4. It is possible to bypass/evade any HTTP-based signature by faking an RST TCP packet with random TCP options of the md5header from the client side. After the three-way handshake, it's possible to inject an RST ACK with a random TCP md5header option. Then, the client can send an HTTP GET request with a forbidden URL. The server will ignore the RST ACK and send the response HTTP packet for the client's request. These packets will not trigger a Suricata reject action.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45098

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 6
Os 3

Sources (Detail)

Source Url
MISC https://forum.suricata.io/t/suricata-6-0-4-and-5-0-8-released/1942
https://github.com/OISF/suricata/commit/50e2b973eeec7172991bf8f544ab06fb782b97df
https://github.com/OISF/suricata/releases
https://redmine.openinfosecfoundation.org/issues/4710

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
Date Informations
2023-04-18 13:03:41
  • Multiple Updates
2022-01-04 21:23:01
  • Multiple Updates
2021-12-17 01:50:12
  • Multiple Updates
2021-12-17 01:50:11
  • Multiple Updates
2021-12-16 17:22:52
  • Multiple Updates
2021-12-16 09:22:56
  • First insertion