CVE-2021-27080 is a critical Azure Sphere Unsigned Code Execution Vulnerability affecting Microsoft Azure Sphere products. With a CVSS score of 9.3, it allows an attacker to execute arbitrary code with high privileges, leading to complete compromise of confidentiality, integrity, and availability, without requiring user interaction or prior authentication. While there are no known public exploits or active exploitation (not in KEV), its high FAUCET Risk Score of 73/100 and mention in a Patch Tuesday article indicate its significant potential impact. Community discussion and media coverage are minimal, suggesting limited public awareness despite its severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_sphere:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.3 Mastodon, and 1.0 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.