HIGH

CVE-2021-32706

CVSS v3

8.8

HIGH

EPSS Score

61.0%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the `validDomainWildcard` preg_match filter allows a malicious character through that can be used to execute code, list directories, and overwrite sensitive files. The issue lies in the fact that one of the periods is not escaped, allowing any character to be used in its place. A patch for this vulnerability was released in version 5.5.1.

Technical details

Published
8/4/2021

Frequently asked questions

What is CVE-2021-32706?

Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the `validDomainWildcard` preg_match filter allows a malicious character through that can be used to execute code, list directories, and overwrite sensitive files. The issue lies in the fact that one of the periods is not escaped, allowing any character to be used in its place. A patch for this vulnerability was released in version 5.5.1.

Is CVE-2021-32706 actively exploited?

Active exploitation of CVE-2021-32706 has not been confirmed. The EPSS score is 61.0%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-32706?

CVE-2021-32706 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2021-32706 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.