CVE-2021-29424 describes an IP address validation vulnerability in the Perl Net::Netmask module (before version 2.0000) that allows attackers to bypass access controls by using IP address strings with extraneous leading zero characters. This high-severity vulnerability (CVSS 7.5) is easily exploitable over the network with no user interaction, potentially leading to unauthorized access. While there are no known public exploits or active exploitation, the vulnerability has garnered significant community and media attention, indicating its potential impact across various applications and languages beyond Perl, including Go, Rust, and Python.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0000CPE matchmatch criteria | cpe:2.3:a:net\:\:netmask_project:net\:\:netmask:*:*:*:*:*:perl:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.