CVE-2021-42377

CRITICAL

An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& str...

Affects 19 products across 5 vendors.

BCS8.11
CVSS 3.19.8
EPSS3.4%
Percentile87th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-590: CWE-590
CWE-763: CWE-763
◆ SAGE Intelligence — CITED Relevance Research Team

CVE-2021-42377 affects the hush applet in Busybox, leading to a denial of service and potential remote code execution if an attacker can control a pointer free during shell command processing. The vulnerability is rated as high severity with a CVSS score of 9.8, indicating critical impact on confidentiality, integrity, and availability. Affected vendors include Busybox, Fedora, Fujitsu-Siemens, NetApp, and Siemens. No public proof of concept or known exploits exist, but the risk remains significant in environments where untrusted input is processed by the shell.

BSID: BS-2021-GLOBAL-073346-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2021-42377?
CVE-2021-42377 affects the hush applet in Busybox, leading to a denial of service and potential remote code execution if an attacker can control a pointer free during shell command processing. The vulnerability is rated as high severity with a CVSS score of 9.8, indicating critical impact on confidentiality, integrity, and availability. Affected vendors include Busybox, Fedora, Fujitsu-Siemens, NetApp, and Siemens. No public proof of concept or known exploits exist, but the risk remains signific
What is the CVSS score for CVE-2021-42377?
CVE-2021-42377 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 3.4%.
Is CVE-2021-42377 actively exploited?
No confirmed active exploitation of CVE-2021-42377 as of 2026-05-30.
How do I remediate CVE-2021-42377?
Priority: HIGH.
What systems are affected by CVE-2021-42377?
CVE-2021-42377 affects: Busybox, Fedoraproject, Fujitsu-Siemens, Netapp, Netapp, Netapp, Netapp, Netapp.
What NERC-CIP standard applies to CVE-2021-42377?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 because it allows unauthorized access to electronic security perimeters, which could lead to the compromise of critical cyber assets.
What IEC 62443 requirement maps to CVE-2021-42377?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 because it involves a vulnerability in a system component that could be exploited to cause a denial of service or execute arbitrary code, both of which can compromise the security of the industrial control system.
Vulnerability Details
CVE IDCVE-2021-42377
BSIDBS-2021-GLOBAL-073346-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2021-11-15
Last Modified2024-11-21
ICS Relevance75%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare conditions of filtered command input.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability arises from the hush applet in Busybox mishandling the '&&&' string in shell commands. If an attacker can control the input to the shell, they can trigger a pointer free that results in a denial of service or potentially execute arbitrary code. This can occur remotely without user interaction, making it particularly dangerous in networked environments where the shell is exposed to untrusted input.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Busybox Busybox
Fedoraproject Fedora
Fujitsu-Siemens —
Netapp Cloud Backup
Netapp H300S Firmware
Netapp H300S
Netapp H500S Firmware
Netapp H500S
Netapp H700S
Netapp H300E Firmware
Netapp H300E
Netapp H500E Firmware
Netapp H500E
Netapp H700E Firmware
Netapp H700E
Netapp H410S Firmware
Netapp H410S
Netapp H700S Firmware
Netapp Hci Management Node
Netapp Solidfire
Siemens —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 1699 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement strict input validation and sanitization for all shell commands, especially those that can be influenced by external sources. Consider using a more secure shell alternative or disabling the hush applet if not essential.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 because it allows unauthorized access to electronic security perimeters, which could lead to the compromise of critical cyber assets.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 because it involves a vulnerability in a system component that could be exploited to cause a denial of service or execute arbitrary code, both of which can compromise the security of the industrial control system.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash631a7130791a5daa3dfac25d87f98679eb9af925c40f2314a6ce7f908a52c6731800d9d208f115dfca071e1ba6b99d0b8887e95ed2a7c9f9c8ec288603d014f0
Related CVEs affecting Busybox
CVE-2022-48174 9.8 There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35.... CVE-2018-1000517 9.8 BusyBox project BusyBox wget version prior to commit 8e2174e9bd836e53c8b9c6e0... CVE-2016-2148 9.8 Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25... CVE-2017-16544 8.8 In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the ... CVE-2022-28391 8.8 BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if n...
View all Busybox CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →