AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-4467

UNKNOWN · CVSS N/A EPSS 0.45%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-11-14 · Last synced 2026-08-04

CyberRota Analysis

This vulnerability has an unknown severity rating. It may be remotely exploitable. It may lead to a denial-of-service condition.

CVE
CVE-2021-4467
Severity
UNKNOWN
CVSS
N/A
EPSS
0.45%

Original NVD Description

Positive Technologies MaxPatrol 8 and XSpider contain a remote denial-of-service vulnerability in the client communication service on TCP port 2002. The service generates a new session identifier for each incoming connection without adequately limiting concurrent requests. An unauthenticated remote attacker can repeatedly issue HTTPS requests to the service, causing excessive allocation of session identifiers. Under load, session identifier collisions may occur, forcing active client sessions to disconnect and resulting in service disruption.