CVE-2021-42377
An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& str...
Affects 19 products across 5 vendors.
CVE-2021-42377 affects the hush applet in Busybox, leading to a denial of service and potential remote code execution if an attacker can control a pointer free during shell command processing. The vulnerability is rated as high severity with a CVSS score of 9.8, indicating critical impact on confidentiality, integrity, and availability. Affected vendors include Busybox, Fedora, Fujitsu-Siemens, NetApp, and Siemens. No public proof of concept or known exploits exist, but the risk remains significant in environments where untrusted input is processed by the shell.
BSID: BS-2021-GLOBAL-073346-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2021-42377?
What is the CVSS score for CVE-2021-42377?
Is CVE-2021-42377 actively exploited?
How do I remediate CVE-2021-42377?
What systems are affected by CVE-2021-42377?
What NERC-CIP standard applies to CVE-2021-42377?
What IEC 62443 requirement maps to CVE-2021-42377?
| CVE ID | CVE-2021-42377 |
|---|---|
| BSID | BS-2021-GLOBAL-073346-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2021-11-15 |
| Last Modified | 2024-11-21 |
| ICS Relevance | 75% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare conditions of filtered command input.
Source: NIST NVD / MITRE CVE Database
The vulnerability arises from the hush applet in Busybox mishandling the '&&&' string in shell commands. If an attacker can control the input to the shell, they can trigger a pointer free that results in a denial of service or potentially execute arbitrary code. This can occur remotely without user interaction, making it particularly dangerous in networked environments where the shell is exposed to untrusted input.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Busybox | Busybox | — |
| Fedoraproject | Fedora | — |
| Fujitsu-Siemens | — | — |
| Netapp | Cloud Backup | — |
| Netapp | H300S Firmware | — |
| Netapp | H300S | — |
| Netapp | H500S Firmware | — |
| Netapp | H500S | — |
| Netapp | H700S | — |
| Netapp | H300E Firmware | — |
| Netapp | H300E | — |
| Netapp | H500E Firmware | — |
| Netapp | H500E | — |
| Netapp | H700E Firmware | — |
| Netapp | H700E | — |
| Netapp | H410S Firmware | — |
| Netapp | H410S | — |
| Netapp | H700S Firmware | — |
| Netapp | Hci Management Node | — |
| Netapp | Solidfire | — |
| Siemens | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement strict input validation and sanitization for all shell commands, especially those that can be influenced by external sources. Consider using a more secure shell alternative or disabling the hush applet if not essential.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 because it allows unauthorized access to electronic security perimeters, which could lead to the compromise of critical cyber assets.
This CVE maps to SR 7.6 because it involves a vulnerability in a system component that could be exploited to cause a denial of service or execute arbitrary code, both of which can compromise the security of the industrial control system.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 631a7130791a5daa3dfac25d87f98679eb9af925c40f2314a6ce7f908a52c6731800d9d208f115dfca071e1ba6b99d0b8887e95ed2a7c9f9c8ec288603d014f0 |
Critical Severity - Know Your Exposure
A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →