CVE-2021-37592: Critical severity suricata vulnerability
Published Nov 19, 2021
·Updated
Suricata before 5.0.8 and 6.x before 6.0.4 allows TCP evasion via a client with a crafted TCP/IP stack that can send a certain sequence of segments.
Affected Software
2 affected components
OISF Suricata<5.0.8
OISF Suricata>=6.0.0<6.0.4
Event History
Nov 19, 2021
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
Description
Frequently Asked Questions
1
What is CVE-2021-37592?
CVE-2021-37592 is a vulnerability in Suricata before 5.0.8 and 6.x before 6.0.4 that allows TCP evasion via a client with a crafted TCP/IP stack that can send a certain sequence of segments.
2
How severe is CVE-2021-37592?
CVE-2021-37592 has a severity rating of 9.8 (Critical).
3
Which software versions are affected by CVE-2021-37592?
Suricata versions before 5.0.8 and between 6.0.0 and 6.0.4 are affected by CVE-2021-37592.
4
How can I fix CVE-2021-37592?
To fix CVE-2021-37592, update Suricata to version 5.0.8 or 6.0.4 depending on the affected version.
5
Where can I find more information about CVE-2021-37592?
You can find more information about CVE-2021-37592 in the Suricata forum, Suricata GitHub releases, and the Open Infosec Foundation Redmine.