CVE-2021-23017
HIGH 7.7EPSS 53.5%
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
- CVSS v3.1
- 7.7 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L - CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P - EPSS
- 53.46% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2021-06-01
- Updated
- 2024-08-03
Proof-of-concept exploits (8)
- 6lj/EVIL-CVE-2021-23017-Update-20251★ · 2025-09-05
- M507/CVE-2021-23017-PoC135★ · 2023-11-12
- ShivamDey/CVE-2021-230170★ · 2023-10-21
- lakshit1212/CVE-2021-23017-PoC1★ · 2023-07-20
- lukwagoasuman/-home-lukewago-Downloads-CVE-2021-23017-Nginx-1.140★ · 2025-01-30
- moften/CVE-2021-230170★ · 2025-05-06
- moften/MalformedDNSQueryNginx0★ · 2025-03-06
- z3usx01/CVE-2021-23017-POC1★ · 2024-12-08