CVE-2021-21702

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP server could return malformed XML data as a response that would cause PHP to access a null pointer and thus cause a crash.

References

https://bugs.php.net/bug.php?id=80672

https://www.debian.org/security/2021/dsa-4856

https://security.netapp.com/advisory/ntap-20210312-0005/

https://security.gentoo.org/glsa/202105-23

https://lists.debian.org/debian-lts-announce/2021/07/msg00008.html

Details

Source: MITRE

Published: 2021-02-15

Updated: 2021-07-22

Type: CWE-476

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 3.9

Severity: HIGH

Tenable Plugins

View all (19 total)

IDNameProductFamilySeverity
151985Tenable.sc < 5.19.0 Multiple Vulnerabilities (TNS-2021-14)NessusMisc.
high
151676Debian DLA-2708-1 : php7.0 - LTS security updateNessusDebian Local Security Checks
critical
151583Ubuntu 16.04 LTS : PHP vulnerabilities (USN-5006-2)NessusUbuntu Local Security Checks
critical
151444Ubuntu 18.04 LTS / 20.04 LTS / 20.10 / 21.04 : PHP vulnerabilities (USN-5006-1)NessusUbuntu Local Security Checks
critical
151173EulerOS Virtualization for ARM 64 3.0.6.0 : php (EulerOS-SA-2021-2006)NessusHuawei Local Security Checks
high
150675SUSE SLES11 Security Update : php53 (SUSE-SU-2021:14668-1)NessusSuSE Local Security Checks
high
149532EulerOS 2.0 SP8 : php (EulerOS-SA-2021-1883)NessusHuawei Local Security Checks
high
146849SUSE SLES15 Security Update : php7 (SUSE-SU-2021:0584-1)NessusSuSE Local Security Checks
high
146688openSUSE Security Update : php7 (openSUSE-2021-305)NessusSuSE Local Security Checks
high
146669SUSE SLES12 Security Update : php74 (SUSE-SU-2021:0522-1)NessusSuSE Local Security Checks
high
146613Debian DSA-4856-1 : php7.3 - security updateNessusDebian Local Security Checks
medium
146579SUSE SLES12 Security Update : php72 (SUSE-SU-2021:0498-1)NessusSuSE Local Security Checks
high
146577SUSE SLED15 / SLES15 Security Update : php7 (SUSE-SU-2021:0494-1)NessusSuSE Local Security Checks
high
146469Fedora 32 : php (2021-ae5a54ba78)NessusFedora Local Security Checks
high
112702PHP 7.3.x < 7.3.27 Null Dereference VulnerabilityWeb Application ScanningComponent Vulnerability
high
112701PHP 7.4.x < 7.4.15 Null Dereference VulnerabilityWeb Application ScanningComponent Vulnerability
high
112700PHP 8.x < 8.0.2 Null Dereference VulnerabilityWeb Application ScanningComponent Vulnerability
high
146311PHP 7.3.x < 7.3.27 / 7.4.x < 7.4.15 / 8.x < 8.0.2 DoSNessusCGI abuses
high
146290Fedora 33 : php (2021-6edfd606d3)NessusFedora Local Security Checks
high