Improper authorization in Net-CIDR-Lite - CVE-2021-47154
Published: March 22, 2024
Vulnerability identifier: #VU87746
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-47154
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to improper input validation when processing extraneous zero characters at the beginning of an IP address string. A remote attacker can bypass access restrictions based on IP addresses.
Affected software
Net-CIDR-Lite
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
Development Tools Module
openSUSE Leap
Ubuntu
openEuler
IBM Qradar SIEM
libnet-cidr-lite-perl (Ubuntu package)
perl-Net-CIDR-Lite
perl-Net-CIDR-Lite-help
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
Development Tools Module
openSUSE Leap
Ubuntu
openEuler
IBM Qradar SIEM
libnet-cidr-lite-perl (Ubuntu package)
perl-Net-CIDR-Lite
perl-Net-CIDR-Lite-help
How to mitigate CVE-2021-47154
Install updates from vendor's website.
Net-CIDR-Lite - update to 0.22
IBM Qradar SIEM - update to 7.5.0 Update Pack 15 IF05
libnet-cidr-lite-perl (Ubuntu package) - addressed in versions 0.21-1ubuntu0.16.04.1~esm1, 0.21-1ubuntu0.18.04.1~esm1, 0.21-2ubuntu0.1, 0.21-2ubuntu0.1+esm1, 0.22-1ubuntu0.1, 0.22-2ubuntu0.24.04.1, 0.22-2ubuntu0.25.10.1, 0.22-2ubuntu0.26.04.1
perl-Net-CIDR-Lite - update to 0.21-24
perl-Net-CIDR-Lite-help - update to 0.21-24
perl-Net-CIDR-Lite - update to 0.21-150100.6.3.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 15 IF05
libnet-cidr-lite-perl (Ubuntu package) - addressed in versions 0.21-1ubuntu0.16.04.1~esm1, 0.21-1ubuntu0.18.04.1~esm1, 0.21-2ubuntu0.1, 0.21-2ubuntu0.1+esm1, 0.22-1ubuntu0.1, 0.22-2ubuntu0.24.04.1, 0.22-2ubuntu0.25.10.1, 0.22-2ubuntu0.26.04.1
perl-Net-CIDR-Lite - update to 0.21-24
perl-Net-CIDR-Lite-help - update to 0.21-24
perl-Net-CIDR-Lite - update to 0.21-150100.6.3.1
External References
Related Security Bulletins
- Improper authorization in Net::CIDR::Lite module
- openEuler 20.03 LTS SP1 update for perl-Net-CIDR-Lite
- openEuler 20.03 LTS SP4 update for perl-Net-CIDR-Lite
- openEuler 22.03 LTS update for perl-Net-CIDR-Lite
- Ubuntu update for libnet-cidr-lite-perl
- SUSE update for perl-Net-CIDR-Lite
- Multiple vulnerabilities in IBM QRadar SIEM
- Ubuntu update for libnet-cidr-lite-perl