Database/Control plane, storage & DevOps
etcd: Authentication flaw via the debug function
CVSS 9.8CVE-2021-28235Control plane, storage & DevOpscurated
Impact
Authentication flaw via the debug function -> remote privilege escalation
Who can reach it
Network (remote)
What to do
Control-plane: CRITICAL - etcd holds every k8s secret; upgrade + rotate all stored secrets
References
Related entries
- etcd: Gateway can be pointed at itself, causing an infinite loop and control-plane DoSCVE-2020-15114 · etcdHigh
- etcd: Gateway TLS authentication applied only to endpoints found in DNS SRV recordsCVE-2020-15136 · etcdMedium
- etcd: No password length validation permits one-character etcd passwordsCVE-2020-15115 · etcdMedium
- etcd: LeaseTimeToLive exposes key names to a user without read permission on those keysCVE-2023-32082 · etcdLow
- Siemens APOGEE PXC / MEC / MBC and TALON TC BACnet and P2 automation controllers: A cluster of critical flawsCVE-2021-31884 · Siemens APOGEE PXC / MEC / MBC and TALON TC BACnet and P2 automation controllersCritical
- Moxa NPort IAW5000A-I/O serial device server: The built-in web server doesn't validate input properly, letting a remoteCVE-2021-32974 · Moxa NPort IAW5000A-I/O serial device serverCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.