CVE-2022-21716 is a high-severity denial-of-service vulnerability affecting the Twisted SSH client and server, present in versions prior to 22.2.0, as well as various distributions like Debian, Fedora, and Oracle. The flaw allows an unauthenticated attacker to exhaust all available memory by sending an infinite amount of data as the SSH version identifier, leading to a system crash. With a CVSS score of 7.5, this vulnerability is easily exploitable over the network with low attack complexity and no user interaction required, resulting in a complete loss of availability. While there are no known workarounds, a patch is available in Twisted version 22.2.0. There is currently no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and limited community discussion, suggesting low current exploitability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 21.7.0, < 22.2.0CPE matchmatch criteria | cpe:2.3:a:twisted:twisted:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
12.2.1.3.0CPE matchmatch criteria | cpe:2.3:a:oracle:http_server:12.2.1.3.0:*:*:*:*:*:*:* | ||
12.2.1.4.0CPE matchmatch criteria | cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:* | ||
8.8CPE matchmatch criteria | cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.