CVE-2022-21309
Published: 19 January 2022
Summary
CVE-2022-21309 is a medium-severity an unspecified weakness vulnerability in Oracle Mysql. Its CVSS base score is 6.3 (Medium).
Operationally, ranked in the top 6.2% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
Deeper analysis
CVE-2022-21309 affects the Cluster: General component of Oracle MySQL Cluster in versions 7.4.34 and earlier, 7.5.24 and earlier, 7.6.20 and earlier, and 8.0.27 and earlier. The flaw is rated CVSS 6.3 and stems from insufficient protections on the physical network segment connecting cluster nodes, enabling a high-privileged attacker who can observe or inject traffic to achieve full cluster takeover when combined with social engineering of another user.
An attacker must already possess administrative credentials on a node reachable via the cluster interconnect and must persuade a second party to perform an action that completes the exploit chain. Successful exploitation grants the attacker control over confidentiality, integrity, and availability of the MySQL Cluster instance.
Oracle’s January 2022 Critical Patch Update and the associated NetApp advisory recommend applying the fixes released for the affected MySQL Cluster releases; the Zero Day Initiative entry ZDI-22-094 further confirms vendor acknowledgment of the issue.
The EPSS score has remained flat at its recorded peak of 0.1143 with no material post-disclosure increase.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2022-26534
Vulnerability details
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with…
more
access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.