CVE-2021-42375 is a denial-of-service vulnerability in Busybox's ash applet, affecting Busybox, Fedora Project, and NetApp products. It arises from incorrect handling of special characters in crafted shell commands, causing the shell to misinterpret them as reserved characters. Rated Medium (CVSS 5.5), this vulnerability requires local access and low privileges to trigger a denial of service, but only under rare conditions of filtered command input. There is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, though it has received limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.33.1CPE matchmatch criteria | cpe:2.3:a:busybox:busybox:1.33.1:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:hci_management_node:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.