Improper authorization in Net-CIDR-Lite - CVE-2021-47154

 

Improper authorization in Net-CIDR-Lite - CVE-2021-47154

Published: March 22, 2024


Vulnerability identifier: #VU87746
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-47154
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to improper input validation when processing extraneous zero characters at the beginning of an IP address string. A remote attacker can bypass access restrictions based on IP addresses.


Affected software

Net-CIDR-Lite
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
Development Tools Module
openSUSE Leap
Ubuntu
openEuler
IBM Qradar SIEM
libnet-cidr-lite-perl (Ubuntu package)
perl-Net-CIDR-Lite
perl-Net-CIDR-Lite-help

How to mitigate CVE-2021-47154

Install updates from vendor's website.

Net-CIDR-Lite - update to 0.22
IBM Qradar SIEM - update to 7.5.0 Update Pack 15 IF05
libnet-cidr-lite-perl (Ubuntu package) - addressed in versions 0.21-1ubuntu0.16.04.1~esm1, 0.21-1ubuntu0.18.04.1~esm1, 0.21-2ubuntu0.1, 0.21-2ubuntu0.1+esm1, 0.22-1ubuntu0.1, 0.22-2ubuntu0.24.04.1, 0.22-2ubuntu0.25.10.1, 0.22-2ubuntu0.26.04.1
perl-Net-CIDR-Lite - update to 0.21-24
perl-Net-CIDR-Lite-help - update to 0.21-24
perl-Net-CIDR-Lite - update to 0.21-150100.6.3.1

External References

Related Security Bulletins