CVE-2021-25217 is a vulnerability in ISC DHCP, affecting versions 4.1-ESV-R1 through 4.1-ESV-R16 and 4.4.0 through 4.4.2, which can lead to denial of service or data loss. Specifically, a crafted lease file can cause dhclient to crash on 32-bit systems, or dhcpd to crash and improperly delete lease entries, particularly on 32-bit architectures or without specific compiler flags. This vulnerability is rated High severity (CVSS 7.4), with an attack vector of Adjacent Network, Low attack complexity, and no user interaction required. The primary impact is High availability loss, as affected DHCP services or clients can cease operation, and in some dhcpd configurations, lease data can be deleted. There is currently no evidence of active exploitation, nor are there publicly available exploit codes in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.4, < 4.4.2-P1CPE match | cpe:2.3:a:isc:dhcpd:*:*:*:*:*:*:*:* | ||
>= 4.4.0, <= 4.4.2CPE matchmatch criteria | cpe:2.3:a:isc:dhcp:*:*:*:*:*:*:*:* | ||
4.1-esvCPE matchmatch criteria | cpe:2.3:a:isc:dhcp:4.1-esv:r1:*:*:*:*:*:* | ||
4.1-esvCPE matchmatch criteria | cpe:2.3:a:isc:dhcp:4.1-esv:r10:*:*:*:*:*:* | ||
4.1-esvCPE matchmatch criteria | cpe:2.3:a:isc:dhcp:4.1-esv:r10_b1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
dhcp: stack-based buffer overflow when parsing statements with colon-separated hex digits in config or lease files in dhcpd and dhclient
May 26, 2021A buffer overrun in lease file parsing code can be used to exploit a common vulnerability shared by dhcpd and dhclient
May 11, 2021