CVE-2021-2425 is a vulnerability in the Optimizer component of Oracle MySQL Server, affecting versions 8.0.25 and prior. This flaw allows a highly privileged attacker with network access to cause a complete denial of service (DoS) by repeatedly crashing the MySQL Server. The vulnerability has a CVSS 3.1 Base Score of 4.9 (Medium), indicating a low attack complexity and requiring high privileges for exploitation. Successful attacks primarily impact availability, leading to a system hang or frequent crashes. Currently, there is no evidence of active exploitation, nor is there publicly available exploit code in Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, which is typical for the majority of vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, <= 8.0.25CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.