CVE-2021-31807 is an integer overflow vulnerability in Squid versions before 4.15 and 5.x before 5.0.6, affecting various Fedora and NetApp products utilizing Squid. This flaw allows a remote server to trigger a Denial of Service (DoS) by crafting HTTP Range requests, utilizing a common header that doesn't inherently indicate malicious intent. With a CVSS score of 6.5 (Medium), it presents a low-complexity attack vector that can lead to high availability impact. While not actively exploited in the wild or on the CISA KEV catalog, a Metasploit module exists, and its high EPSS and FAUCET Risk Score indicate a significant potential for exploitation. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0, < 4.15CPE matchmatch criteria | cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:* | ||
>= 5.0, < 5.0.6CPE matchmatch criteria | cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:* | ||
2.5.stable2CPE matchmatch criteria | cpe:2.3:a:squid-cache:squid:2.5.stable2:*:*:*:*:*:*:* | ||
2.5.stable3CPE matchmatch criteria | cpe:2.3:a:squid-cache:squid:2.5.stable3:*:*:*:*:*:*:* | ||
2.5.stable4CPE matchmatch criteria | cpe:2.3:a:squid-cache:squid:2.5.stable4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.