Vulnerability Description
In Dekart Private Disk 2.15, invalid use of the Type3 user buffer for IOCTL codes using METHOD_NEITHER results in arbitrary memory dereferencing.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dekart | Private Disk | 2.15 |
Related Weaknesses (CWE)
References
- https://www.dekart.com/products/encryption/private_diskProductVendor Advisory
- https://www.rootshellsecurity.net/rootshell-discover-denial-of-service-flaw-dekaExploitThird Party Advisory
- https://www.dekart.com/products/encryption/private_diskProductVendor Advisory
- https://www.rootshellsecurity.net/rootshell-discover-denial-of-service-flaw-dekaExploitThird Party Advisory
FAQ
What is CVE-2021-27203?
CVE-2021-27203 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In Dekart Private Disk 2.15, invalid use of the Type3 user buffer for IOCTL codes using METHOD_NEITHER results in arbitrary memory dereferencing.
How severe is CVE-2021-27203?
CVE-2021-27203 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-27203?
Check the references section above for vendor advisories and patch information. Affected products include: Dekart Private Disk.