CVE-2021-27376 is a critical vulnerability affecting the nb-connect Rust crate prior to version 1.0.3, stemming from invalid memory access due to direct casting of standard library socket address structures. With a CVSS score of 9.8, it presents a critical risk, allowing for remote, low-complexity attacks that can lead to complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion with over 10 mentions, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.3CPE matchmatch criteria | cpe:2.3:a:nb-connect_project:nb-connect:*:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.