« Volver al listado

CVE-2021-21439

Estado: ModificadaMedia (6.5)—

DoS attack can be performed when an email contains specially designed URL in the body. It can lead to the high CPU usage and cause low quality of service, or in extreme case bring the system to a halt. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.26 and prior versions; 8.0.x version 8.0.13 and prior versions.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-21439",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@otrs.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@otrs.com",
      "affectedData": [
        {
          "vendor": "OTRS AG",
          "product": "((OTRS)) Community Edition",
          "versions": [
            {
              "status": "affected",
              "version": "6.0.1",
              "lessThan": "6.0.x*",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "OTRS AG",
          "product": "OTRS",
          "versions": [
            {
              "status": "affected",
              "version": "7.0.x",
              "versionType": "custom",
              "lessThanOrEqual": "7.0.26"
            },
            {
              "status": "affected",
              "version": "8.0.x",
              "versionType": "custom",
              "lessThanOrEqual": "8.0.13"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-06-14T08:15:10.097",
  "references": [
    {
      "url": "https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html",
      "source": "security@otrs.com"
    },
    {
      "url": "https://otrs.com/release-notes/otrs-security-advisory-2021-09/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@otrs.com"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://otrs.com/release-notes/otrs-security-advisory-2021-09/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@otrs.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-754"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-755"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "DoS attack can be performed when an email contains specially designed URL in the body. It can lead to the high CPU usage and cause low quality of service, or in extreme case bring the system to a halt. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.26 and prior versions; 8.0.x version 8.0.13 and prior versions."
    },
    {
      "lang": "es",
      "value": "El ataque de DoS puede ser llevado a cabo cuando un correo electrónico contiene una URL especialmente diseñada en el cuerpo. Puede conllevar a un alto uso de la CPU y causar una baja calidad de servicio, o en caso extremo llevar el sistema a una parada. Este problema afecta a: OTRS AG ((OTRS)) Community Edition versión 6.0.x, 6.0.1 y versiones posteriores. OTRS AG OTRS versión 7.0.x, 7.0.26 y versiones anteriores; versión 8.0.x,  8.0.13 y versiones anteriores"
    }
  ],
  "lastModified": "2026-06-17T03:35:34.680",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:otrs:otrs:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "58EDB086-8414-4EBD-8C19-1402C800DFD6",
              "versionEndIncluding": "6.0.30",
              "versionStartIncluding": "6.0.1"
            },
            {
              "criteria": "cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4FDBB41C-E915-41DF-8E95-8BB17798F20A",
              "versionEndExcluding": "7.0.27",
              "versionStartIncluding": "7.0.0"
            },
            {
              "criteria": "cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "042B7D35-918B-4716-A819-9AE29ECF50AD",
              "versionEndExcluding": "8.0.14",
              "versionStartIncluding": "8.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@otrs.com"
}