Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-27212

58
FAUCET Score

CVE-2021-27212 describes a denial-of-service vulnerability affecting OpenLDAP versions through 2.4.57 and 2.5.x through 2.5.1alpha, specifically impacting Debian Linux distributions. This flaw allows an unauthenticated attacker to cause the slapd daemon to crash by sending a specially crafted packet with a short timestamp, triggering an assertion failure. Rated with a CVSS score of 7.5 (High), the vulnerability is easily exploitable over the network with low complexity and no user interaction, leading to a complete loss of availability. While the EPSS score indicates a moderate likelihood of exploitation, there is currently no public exploit code available, nor any evidence of active exploitation or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.4.57CPE matchmatch criteria
cpe:2.3:a:openldap:openldap:*:*:*:*:*:*:*:*
2.5.0CPE matchmatch criteria
cpe:2.3:a:openldap:openldap:2.5.0:alpha:*:*:*:*:*:*
2.5.1CPE matchmatch criteria
cpe:2.3:a:openldap:openldap:2.5.1:alpha:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
64.15%
Probability of exploitation in next 30 days
EPSS Percentile
99.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.6415 is in the 99th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (18)

mediatekpatch availablevia llm_extracted
Fixed in: 9.3.1, 9.2.3, 9.1.6
microsoftpatch availablevia msrc
Product: 13463-12137Fixed in: 2.4.57-2
microsoftpatch availablevia msrc
Product: 13464-12138Fixed in: 2.4.57-2
microsoftpatch availablevia msrc
Product: 13465-12138Fixed in: 2.4.57-2
microsoftpatch availablevia msrc
Product: 13466-12139Fixed in: 2.4.57-6
microsoftpatch availablevia msrc
Product: 13467-12139Fixed in: 2.4.57-6
microsoftpatch availablevia msrc
Product: 13468-12140Fixed in: 2.4.57-6
microsoftpatch availablevia msrc
Product: 13469-12140Fixed in: 2.4.57-6
microsoftpatch availablevia msrc
Product: openldap-debuginfo-2.4.57-6.cm2.aarch64.rpm on CBL Mariner 2.0 ARMFixed in: 2.4.57-6
microsoftpatch availablevia msrc
Product: 13462-12137Fixed in: 2.4.57-2
microsoftpatch availablevia msrc
Product: openldap-2.4.57-2.cm1.x86_64.rpm on CBL Mariner 1.0 x64Fixed in: 2.4.57-2
microsoftpatch availablevia msrc
Product: openldap-debuginfo-2.4.57-2.cm1.x86_64.rpm on CBL Mariner 1.0 x64Fixed in: 2.4.57-2
microsoftpatch availablevia msrc
Product: openldap-2.4.57-2.cm1.aarch64.rpm on CBL Mariner 1.0 ARMFixed in: 2.4.57-2
microsoftpatch availablevia msrc
Product: openldap-debuginfo-2.4.57-2.cm1.aarch64.rpm on CBL Mariner 1.0 ARMFixed in: 2.4.57-2
microsoftpatch availablevia msrc
Product: openldap-2.4.57-6.cm2.x86_64.rpm on CBL Mariner 2.0 x64Fixed in: 2.4.57-6
microsoftpatch availablevia msrc
Product: openldap-debuginfo-2.4.57-6.cm2.x86_64.rpm on CBL Mariner 2.0 x64Fixed in: 2.4.57-6
microsoftpatch availablevia msrc
Product: openldap-2.4.57-6.cm2.aarch64.rpm on CBL Mariner 2.0 ARMFixed in: 2.4.57-6
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: openldap

Vendor Advisories (3)

mediatekllm-mediatek-5bd731d14163992dHIGH

Third-Party Package Updates in Splunk Enterprise - October 2024

Oct 14, 2024
redhatCVE-2021-27212Moderate

openldap: Assertion failure in slapd in the issuerAndThisUpdateCheck function

Feb 14, 2021
microsoft2021-Feb/CVE-2021-27212

In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet resulting in a denial of service (daemon exit) via a short timestamp. This is related to schema_init.c and checkTime.

Feb 9, 2021

References

bugs.openldap.org / show_bug.cgi
ExploitIssue TrackingVendor Advisory
git.openldap.org / openldap/openldap/-/commit/3539fc33212b528c56b716584f2c2994af7c30b0
PatchVendor Advisory
git.openldap.org / openldap/openldap/-/commit/9badb73425a67768c09bcaed1a9c26c684af6c30
PatchVendor Advisory
lists.apache.org / thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
lists.apache.org / thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
lists.debian.org / debian-lts-announce/2021/02/msg00035.html
Mailing ListThird Party Advisory
security.netapp.com / advisory/ntap-20210319-0005
Third Party Advisory
debian.org / security/2021/dsa-4860
Third Party Advisory