{"api_version":"1","generated_at":"2026-07-23T20:19:18+00:00","cve":"CVE-2021-3384","urls":{"html":"https://cve.report/CVE-2021-3384","api":"https://cve.report/api/cve/CVE-2021-3384.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-3384","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-3384"},"summary":{"title":"CVE-2021-3384","description":"A vulnerability in Stormshield Network Security could allow an attacker to trigger a protection related to ARP/NDP tables management, which would temporarily prevent the system to contact new hosts via IPv4 or IPv6. This affects versions 2.0.0 to 2.7.7, 2.8.0 to 2.16.0, 3.0.0 to 3.7.16, 3.8.0 to 3.11.4, and 4.0.0 to 4.1.5. Fixed in versions 2.7.8, 3.7.17, 3.11.5, and 4.2.0.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-03-02 18:15:00","updated_at":"2021-03-09 18:30:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://advisories.stormshield.eu/2020-049/","name":"https://advisories.stormshield.eu/2020-049/","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Mishandling of IPv6 NDP timeout (CVE-2021-3384) | Stormshield security","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-3384","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-3384","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"3384","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"stormshield","cpe5":"network_security","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"3384","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"stormshield","cpe5":"network_security","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"3384","vulnerable":"1","versionEndIncluding":"2.16.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"stormshield","cpe5":"network_security","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"3384","vulnerable":"1","versionEndIncluding":"3.11.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"stormshield","cpe5":"network_security","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"3384","vulnerable":"1","versionEndIncluding":"3.7.17","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"stormshield","cpe5":"network_security","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-3384","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A vulnerability in Stormshield Network Security could allow an attacker to trigger a protection related to ARP/NDP tables management, which would temporarily prevent the system to contact new hosts via IPv4 or IPv6. This affects versions 2.0.0 to 2.7.7, 2.8.0 to 2.16.0, 3.0.0 to 3.7.16, 3.8.0 to 3.11.4, and 4.0.0 to 4.1.5. Fixed in versions 2.7.8, 3.7.17, 3.11.5, and 4.2.0."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://advisories.stormshield.eu/2020-049/","url":"https://advisories.stormshield.eu/2020-049/"}]}},"nvd":{"publishedDate":"2021-03-02 18:15:00","lastModifiedDate":"2021-03-09 18:30:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:stormshield:network_security:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0.0","versionEndExcluding":"4.1.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:stormshield:network_security:*:*:*:*:*:*:*:*","versionStartIncluding":"2.8.0","versionEndIncluding":"2.16.0","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:stormshield:network_security:*:*:*:*:*:*:*:*","versionStartIncluding":"2.0.0","versionEndExcluding":"2.7.8","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:stormshield:network_security:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0.0","versionEndIncluding":"3.7.17","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:stormshield:network_security:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8.0","versionEndIncluding":"3.11.5","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"3384","Ordinal":"201600","Title":"CVE-2021-3384","CVE":"CVE-2021-3384","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"3384","Ordinal":"1","NoteData":"A vulnerability in Stormshield Network Security could allow an attacker to trigger a protection related to ARP/NDP tables management, which would temporarily prevent the system to contact new hosts via IPv4 or IPv6. This affects versions 2.0.0 to 2.7.7, 2.8.0 to 2.16.0, 3.0.0 to 3.7.16, 3.8.0 to 3.11.4, and 4.0.0 to 4.1.5. Fixed in versions 2.7.8, 3.7.17, 3.11.5, and 4.2.0.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"3384","Ordinal":"2","NoteData":"2021-03-02","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"3384","Ordinal":"3","NoteData":"2021-03-02","Type":"Other","Title":"Modified"}]}}}