First published: Mon Aug 09 2021(Updated: )
A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3. It allows remote attackers to crash the C2 server thread and block beacons' communication with it.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HelpSystems Cobalt Strike | =4.2 | |
HelpSystems Cobalt Strike | =4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-36798.
The severity of CVE-2021-36798 is high with a CVSS score of 7.5.
The affected software is HelpSystems Cobalt Strike versions 4.2 and 4.3.
CVE-2021-36798 allows remote attackers to crash the C2 server thread and block beacons' communication with it, causing a denial-of-service (DoS) situation.
Yes, you can find references for CVE-2021-36798 at the following links: [Link1](https://labs.sentinelone.com/hotcobalt-new-cobalt-strike-dos-vulnerability-that-lets-you-halt-operations/) and [Link2](https://www.cobaltstrike.com/releasenotes.txt).