CVE-2021-28682 is a remotely exploitable integer overflow vulnerability in Envoy versions up to 1.71.1. A very large grpc-timeout value can lead to incorrect timeout calculations, potentially causing a denial of service. It carries a CVSS score of 7.5 (High), indicating a network-exploitable vulnerability with low attack complexity and high impact on availability. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.14.6CPE matchmatch criteria | cpe:2.3:a:envoyproxy:envoy:1.14.6:*:*:*:*:*:*:* | ||
1.15.3CPE matchmatch criteria | cpe:2.3:a:envoyproxy:envoy:1.15.3:*:*:*:*:*:*:* | ||
1.16.2CPE matchmatch criteria | cpe:2.3:a:envoyproxy:envoy:1.16.2:*:*:*:*:*:*:* | ||
1.17.1CPE matchmatch criteria | cpe:2.3:a:envoyproxy:envoy:1.17.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
envoyproxy/envoy: integer overflow handling large grpc-timeouts
Apr 15, 2021Envoy and Istio Denial of Service Vulnerabilities
Jan 1, 2021The Envoy and Istio projects recently announced several new security vulnerabilities (CVE-2021-28683, CVE-2021-28682 and CVE-2021-29258), that could allow an attacker to crash Envoy.
Envoy and Istio Denial of Service Vulnerabilities