CVE detail
CVE-2021-41617
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 28.9 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
17 source links · newest first
00 CPU 1518(F)-4 PN/DP MFP are affected: SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) vers:intdot/>=3.1.6 (CVE-2021-41617, CVE-2023-28531, CVE-2023-51384, CVE-2023-52927, CVE-2024-26783, CVE-2024-27056, CVE-2024-28956, CVE-2024-36903, CVE-2024-36927, CVE-2024-42079, CVE-2024-46786, CVE-2024-47736, CVE-2024-47809, CVE-2024-49968, CVE-2024-4
governmentwww.cisa.govJul 28, 2026, 12:00 PM- https://cert-portal.siemens.com/productcert/html/ssa-082556.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comSep 26, 2021, 7:15 PM - https://cert-portal.siemens.com/productcert/html/ssa-019113.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comSep 26, 2021, 7:15 PM - https://www.tenable.com/plugins/nessus/154174www.tenable.com
No excerpt available.
Exploitwww.tenable.comSep 26, 2021, 7:15 PM - https://www.starwindsoftware.com/security/sw-20220805-0001/www.starwindsoftware.com
No excerpt available.
Third Party Advisorywww.starwindsoftware.comSep 26, 2021, 7:15 PM - https://www.oracle.com/security-alerts/cpujul2022.htmlwww.oracle.com
No excerpt available.
Vendor Advisorywww.oracle.comSep 26, 2021, 7:15 PM - https://www.oracle.com/security-alerts/cpuapr2022.htmlwww.oracle.com
No excerpt available.
Vendor Advisorywww.oracle.comSep 26, 2021, 7:15 PM - https://www.openwall.com/lists/oss-security/2021/09/26/1www.openwall.com
No excerpt available.
Exploitwww.openwall.comSep 26, 2021, 7:15 PM - https://www.openssh.com/txt/release-8.8www.openssh.com
No excerpt available.
Vendor Advisorywww.openssh.comSep 26, 2021, 7:15 PM - https://www.openssh.com/security.htmlwww.openssh.com
No excerpt available.
Vendor Advisorywww.openssh.comSep 26, 2021, 7:15 PM - https://www.debian.org/security/2023/dsa-5586www.debian.org
No excerpt available.
Vendor Advisorywww.debian.orgSep 26, 2021, 7:15 PM - https://security.netapp.com/advisory/ntap-20211014-0004/security.netapp.com
No excerpt available.
Vendor Advisorysecurity.netapp.comSep 26, 2021, 7:15 PM - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W44V2PFQH5YLRN6ZJTVRKAD7CU6CYYET/lists.fedoraproject.org
No excerpt available.
Third Party Advisorylists.fedoraproject.orgSep 26, 2021, 7:15 PM - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KVI7RWM2JLNMWTOFK6BDUSGNOIPZYPUT/lists.fedoraproject.org
No excerpt available.
Third Party Advisorylists.fedoraproject.orgSep 26, 2021, 7:15 PM - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6XJIONMHMKZDTMH6BQR5TNLF2WDCGWED/lists.fedoraproject.org
No excerpt available.
Third Party Advisorylists.fedoraproject.orgSep 26, 2021, 7:15 PM No excerpt available.
Vendor Advisorylists.debian.orgSep 26, 2021, 7:15 PM- https://bugzilla.suse.com/show_bug.cgi?id=1190975bugzilla.suse.com
No excerpt available.
Exploitbugzilla.suse.comSep 26, 2021, 7:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2021-3517CVSS 8.6 · High
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application l…
- CVE-2021-25214CVSS 6.5 · Medium
In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported Preview Edition, as well as r…
- CVE-2022-1587CVSS 9.1 · Critical
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in…
- CVE-2022-1586CVSS 9.1 · Critical
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode prop…
- CVE-2022-29824CVSS 6.5 · Medium
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory w…
- CVE-2022-0391CVSS 7.5 · High
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the…