CVE-2021-3384
Last modified
CVE-2021-3384 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A vulnerability in Stormshield Network Security could allow an attacker to trigger a protection related to ARP/NDP tables management, which would temporarily prevent the system to contact new hosts via IPv4 or IPv6. This affects versions 2.0.0 to 2.7.7, 2.8.0 to 2.16.0, 3.0.0 to 3.7.16, 3.8.0 to 3.11.4, and 4.0.0 to 4.1.5. EPSS estimates a 1.02% chance of exploitation in the next 30 days.
Description
A vulnerability in Stormshield Network Security could allow an attacker to trigger a protection related to ARP/NDP tables management, which would temporarily prevent the system to contact new hosts via IPv4 or IPv6. This affects versions 2.0.0 to 2.7.7, 2.8.0 to 2.16.0, 3.0.0 to 3.7.16, 3.8.0 to 3.11.4, and 4.0.0 to 4.1.5. Fixed in versions 2.7.8, 3.7.17, 3.11.5, and 4.2.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Stormshield | Stormshield Network Security | >= 2.0.0, < 2.7.8 |
| Stormshield | Stormshield Network Security | >= 2.8.0, <= 2.16.0 |
| Stormshield | Stormshield Network Security | >= 3.0.0, <= 3.7.17 |
| Stormshield | Stormshield Network Security | >= 3.8.0, <= 3.11.5 |
| Stormshield | Stormshield Network Security | >= 4.0.0, < 4.1.5 |
References
- https://advisories.stormshield.eu/2020-049/Vendor Advisory
- https://advisories.stormshield.eu/2020-049/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-3384?
How severe is CVE-2021-3384?
How do I fix CVE-2021-3384?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-33829A cross-site scripting (XSS) vulnerability in the HTML Data …6.1
- CVE-2021-33831api/account/register in the TH Wildau COVID-19 Contact Traci…6.5
- CVE-2021-33833ConnMan (aka Connection Manager) 1.30 through 1.39 has a sta…9.8
- CVE-2021-33834An issue was discovered in iscflashx64.sys 3.9.3.0 in Insyde…7.1
- CVE-2021-33838Luca through 1.7.4 on Android allows remote attackers to obt…7.5
- CVE-2021-33839Luca through 1.7.4 on Android allows remote attackers to obt…7.5
- CVE-2021-33840The server in Luca through 1.1.14 allows remote attackers to…7.5
- CVE-2021-33841SGE-PLC1000 device, in its 0.9.2b firmware version, does not…9.8
- CVE-2021-33842Improper Authentication vulnerability in the cookie paramete…8.8
- CVE-2021-33843Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a defaul…5.3
- CVE-2021-33844A floating point exception (divide-by-zero) issue was discov…5.5
- CVE-2021-33845The Splunk Enterprise REST API allows enumeration of usernam…5.3
Are you affected by CVE-2021-3384?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
