Vulnerabilities > CVE-2021-28683 - NULL Pointer Dereference vulnerability in Envoyproxy Envoy 1.16.2/1.17.1

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
envoyproxy
CWE-476

Summary

An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable NULL pointer dereference and crash in TLS when an unknown TLS alert code is received.

Vulnerable Configurations

Part Description Count
Application
Envoyproxy
2

Common Weakness Enumeration (CWE)