CVE-2021-36798
Summary
| CVE | CVE-2021-36798 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-09 13:15:00 UTC |
| Updated | 2021-08-17 12:49:00 UTC |
| Description | A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3. It allows remote attackers to crash the C2 server thread and block beacons' communication with it. |
Risk And Classification
Problem Types: CWE-770
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Helpsystems | Cobalt Strike | 4.2 | All | All | All |
| Application | Helpsystems | Cobalt Strike | 4.3 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cobalt Strike Release Notes | MISC | www.cobaltstrike.com | |
| Hotcobalt - New Cobalt Strike DoS Vulnerability That Lets You Halt Operations - SentinelLabs | MISC | labs.sentinelone.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.