Vulnerabilities > CVE-2021-28683 - NULL Pointer Dereference vulnerability in Envoyproxy Envoy 1.16.2/1.17.1

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
envoyproxy
CWE-476

Summary

An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable NULL pointer dereference and crash in TLS when an unknown TLS alert code is received.

Vulnerable Configurations

Part Description Count
Application
Envoyproxy
2

Common Weakness Enumeration (CWE)