CVE-2021-2351

Exp

Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Advanced Networking Option, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Advanced Networking Option. Note: The July 2021 Critical Patch Update introduces a number of Native Network Encryption changes to deal with vulnerability CVE-2021-2351 and prevent the use of weaker ciphers. Customers should review: "Changes in Native Network Encryption with the July 2021 Critical Patch Update" (Doc ID 2791571.1). CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).

Published: 2021-07-21 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2021-2351 is rated High Exploit Risk (76.3/100): CVSS High severity, with medium exploitation likelihood (EPSS 2.50%). Core evidence: 4 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2021-2351

EDB-ID Source Kind Published Link
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2021-2351

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 3.30% 2.50% -0.80%
2 2026-05-18 2.77% 3.30% +0.53%
3 2026-04-20 2.77%

Full EPSS history (47 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2021-2351

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
8.3 3.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:H)
Even with access, the exploit needs extra luck, timing, or a fussy environment to actually work.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:R)
A real person has to do something—click, install, enable—otherwise it doesn’t land.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
1.6 6.0 [email protected]
7.5 3.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:H)
Even with access, the exploit needs extra luck, timing, or a fussy environment to actually work.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:R)
A real person has to do something—click, install, enable—otherwise it doesn’t land.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
1.6 5.9 [email protected]
5.1 2.0 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:H)
Exploitation requires uncommon or highly specific conditions.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
4.9 6.4 [email protected]

Weakness enumeration for CVE-2021-2351

Affected software / configurations for CVE-2021-2351

Vendor Product Version Raw CPE
oracle advanced_networking_option 12.1.0.2 cpe:2.3:a:oracle:advanced_networking_option:12.1.0.2:*:*:*:*:*:*:*
oracle advanced_networking_option 12.2.0.1 cpe:2.3:a:oracle:advanced_networking_option:12.2.0.1:*:*:*:*:*:*:*
oracle advanced_networking_option 19c cpe:2.3:a:oracle:advanced_networking_option:19c:*:*:*:*:*:*:*
oracle agile_engineering_data_management 6.2.1.0 cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:*
oracle agile_plm 9.3.6 cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
oracle agile_product_lifecycle_management_for_process 6.2.2.0 cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.2.0:*:*:*:*:*:*:*
oracle agile_product_lifecycle_management_for_process 6.2.3.0 cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.3.0:*:*:*:*:*:*:*
oracle airlines_data_model 12.1.1.0.0 cpe:2.3:a:oracle:airlines_data_model:12.1.1.0.0:*:*:*:*:*:*:*
oracle airlines_data_model 12.2.0.1.0 cpe:2.3:a:oracle:airlines_data_model:12.2.0.1.0:*:*:*:*:*:*:*
oracle application_performance_management 13.4.1.0 cpe:2.3:a:oracle:application_performance_management:13.4.1.0:*:*:*:*:*:*:*
oracle application_performance_management 13.5.1.0 cpe:2.3:a:oracle:application_performance_management:13.5.1.0:*:*:*:*:*:*:*
oracle application_testing_suite 13.3.0.1 cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*
oracle argus_analytics 8.2.1 cpe:2.3:a:oracle:argus_analytics:8.2.1:*:*:*:*:*:*:*
oracle argus_analytics 8.2.2 cpe:2.3:a:oracle:argus_analytics:8.2.2:*:*:*:*:*:*:*
oracle argus_analytics 8.2.3 cpe:2.3:a:oracle:argus_analytics:8.2.3:*:*:*:*:*:*:*
oracle argus_insight 8.2.1 cpe:2.3:a:oracle:argus_insight:8.2.1:*:*:*:*:*:*:*
oracle argus_insight 8.2.2 cpe:2.3:a:oracle:argus_insight:8.2.2:*:*:*:*:*:*:*
oracle argus_insight 8.2.3 cpe:2.3:a:oracle:argus_insight:8.2.3:*:*:*:*:*:*:*
oracle argus_mart 8.2.1 cpe:2.3:a:oracle:argus_mart:8.2.1:*:*:*:*:*:*:*
oracle argus_mart 8.2.2 cpe:2.3:a:oracle:argus_mart:8.2.2:*:*:*:*:*:*:*
oracle argus_mart 8.2.3 cpe:2.3:a:oracle:argus_mart:8.2.3:*:*:*:*:*:*:*
oracle argus_safety 8.2.1 cpe:2.3:a:oracle:argus_safety:8.2.1:*:*:*:*:*:*:*
oracle argus_safety 8.2.2 cpe:2.3:a:oracle:argus_safety:8.2.2:*:*:*:*:*:*:*
oracle argus_safety 8.2.3 cpe:2.3:a:oracle:argus_safety:8.2.3:*:*:*:*:*:*:*
oracle banking_apis >= 18.1, <= 18.3 cpe:2.3:a:oracle:banking_apis:*:*:*:*:*:*:*:*
oracle banking_apis 19.1 cpe:2.3:a:oracle:banking_apis:19.1:*:*:*:*:*:*:*
oracle banking_apis 19.2 cpe:2.3:a:oracle:banking_apis:19.2:*:*:*:*:*:*:*
oracle banking_apis 20.1 cpe:2.3:a:oracle:banking_apis:20.1:*:*:*:*:*:*:*
oracle banking_apis 21.1 cpe:2.3:a:oracle:banking_apis:21.1:*:*:*:*:*:*:*
oracle banking_digital_experience >= 18.1, <= 18.3 cpe:2.3:a:oracle:banking_digital_experience:*:*:*:*:*:*:*:*
oracle banking_digital_experience 17.2 cpe:2.3:a:oracle:banking_digital_experience:17.2:*:*:*:*:*:*:*
oracle banking_digital_experience 19.1 cpe:2.3:a:oracle:banking_digital_experience:19.1:*:*:*:*:*:*:*
oracle banking_digital_experience 19.2 cpe:2.3:a:oracle:banking_digital_experience:19.2:*:*:*:*:*:*:*
oracle banking_digital_experience 20.1 cpe:2.3:a:oracle:banking_digital_experience:20.1:*:*:*:*:*:*:*
oracle banking_digital_experience 21.1 cpe:2.3:a:oracle:banking_digital_experience:21.1:*:*:*:*:*:*:*
oracle banking_enterprise_default_management 2.10.0 cpe:2.3:a:oracle:banking_enterprise_default_management:2.10.0:*:*:*:*:*:*:*
oracle banking_enterprise_default_management 2.12.0 cpe:2.3:a:oracle:banking_enterprise_default_management:2.12.0:*:*:*:*:*:*:*
oracle banking_platform 2.6.2 cpe:2.3:a:oracle:banking_platform:2.6.2:*:*:*:*:*:*:*
oracle banking_platform 2.7.1 cpe:2.3:a:oracle:banking_platform:2.7.1:*:*:*:*:*:*:*
oracle banking_platform 2.12.0 cpe:2.3:a:oracle:banking_platform:2.12.0:*:*:*:*:*:*:*
oracle big_data_spatial_and_graph < 23.1 cpe:2.3:a:oracle:big_data_spatial_and_graph:*:*:*:*:*:*:*:*
oracle blockchain_platform 21.1.2 cpe:2.3:a:oracle:blockchain_platform:21.1.2:*:*:*:*:*:*:*
oracle clinical 5.2.1 cpe:2.3:a:oracle:clinical:5.2.1:*:*:*:*:*:*:*
oracle clinical 5.2.2 cpe:2.3:a:oracle:clinical:5.2.2:*:*:*:*:*:*:*
oracle commerce_platform 11.3.0 cpe:2.3:a:oracle:commerce_platform:11.3.0:*:*:*:*:*:*:*
oracle commerce_platform 11.3.1 cpe:2.3:a:oracle:commerce_platform:11.3.1:*:*:*:*:*:*:*
oracle commerce_platform 11.3.2 cpe:2.3:a:oracle:commerce_platform:11.3.2:*:*:*:*:*:*:*
oracle communications_application_session_controller 3.9.0 cpe:2.3:a:oracle:communications_application_session_controller:3.9.0:*:*:*:*:*:*:*
oracle communications_billing_and_revenue_management 12.0.0.4 cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.4:*:*:*:*:*:*:*
oracle communications_billing_and_revenue_management 12.0.0.5 cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.5:*:*:*:*:*:*:*
oracle communications_calendar_server 8.0.0.5.0 cpe:2.3:a:oracle:communications_calendar_server:8.0.0.5.0:*:*:*:*:*:*:*
oracle communications_contacts_server 8.0.0.3.0 cpe:2.3:a:oracle:communications_contacts_server:8.0.0.3.0:*:*:*:*:*:*:*
oracle communications_convergent_charging_controller >= 12.0.1.0.0, <= 12.0.4.0.0 cpe:2.3:a:oracle:communications_convergent_charging_controller:*:*:*:*:*:*:*:*
oracle communications_convergent_charging_controller 6.0.1.0.0 cpe:2.3:a:oracle:communications_convergent_charging_controller:6.0.1.0.0:*:*:*:*:*:*:*
oracle communications_data_model 11.3.2.1.0 cpe:2.3:a:oracle:communications_data_model:11.3.2.1.0:*:*:*:*:*:*:*
oracle communications_data_model 11.3.2.2.0 cpe:2.3:a:oracle:communications_data_model:11.3.2.2.0:*:*:*:*:*:*:*
oracle communications_data_model 11.3.2.3.0 cpe:2.3:a:oracle:communications_data_model:11.3.2.3.0:*:*:*:*:*:*:*
oracle communications_data_model 12.1.0.1.0 cpe:2.3:a:oracle:communications_data_model:12.1.0.1.0:*:*:*:*:*:*:*
oracle communications_data_model 12.1.2.0.0 cpe:2.3:a:oracle:communications_data_model:12.1.2.0.0:*:*:*:*:*:*:*
oracle communications_design_studio 7.3.5 cpe:2.3:a:oracle:communications_design_studio:7.3.5:*:*:*:*:*:*:*
oracle communications_design_studio 7.4.0 cpe:2.3:a:oracle:communications_design_studio:7.4.0:*:*:*:*:*:*:*
oracle communications_design_studio 7.4.1 cpe:2.3:a:oracle:communications_design_studio:7.4.1:*:*:*:*:*:*:*
oracle communications_design_studio 7.4.2 cpe:2.3:a:oracle:communications_design_studio:7.4.2:*:*:*:*:*:*:*
oracle communications_diameter_intelligence_hub >= 8.0.0, <= 8.2.3 cpe:2.3:a:oracle:communications_diameter_intelligence_hub:*:*:*:*:*:*:*:*
oracle communications_ip_service_activator 7.4.0 cpe:2.3:a:oracle:communications_ip_service_activator:7.4.0:*:*:*:*:*:*:*
oracle communications_metasolv_solution 6.3.1 cpe:2.3:a:oracle:communications_metasolv_solution:6.3.1:*:*:*:*:*:*:*
oracle communications_network_charging_and_control >= 12.0.1.0, <= 12.0.4.0.0 cpe:2.3:a:oracle:communications_network_charging_and_control:*:*:*:*:*:*:*:*
oracle communications_network_charging_and_control 6.0.1.0.0 cpe:2.3:a:oracle:communications_network_charging_and_control:6.0.1.0.0:*:*:*:*:*:*:*
oracle communications_network_integrity 7.3.5 cpe:2.3:a:oracle:communications_network_integrity:7.3.5:*:*:*:*:*:*:*
oracle communications_network_integrity 7.3.6 cpe:2.3:a:oracle:communications_network_integrity:7.3.6:*:*:*:*:*:*:*
oracle communications_pricing_design_center 12.0.0.4 cpe:2.3:a:oracle:communications_pricing_design_center:12.0.0.4:*:*:*:*:*:*:*
oracle communications_pricing_design_center 12.0.0.5 cpe:2.3:a:oracle:communications_pricing_design_center:12.0.0.5:*:*:*:*:*:*:*
oracle communications_services_gatekeeper 7.0 cpe:2.3:a:oracle:communications_services_gatekeeper:7.0:*:*:*:*:*:*:*
oracle communications_session_report_manager >= 8.0.0, <= 8.2.5.0 cpe:2.3:a:oracle:communications_session_report_manager:*:*:*:*:*:*:*:*
oracle communications_session_route_manager >= 8.2.0, <= 8.2.5 cpe:2.3:a:oracle:communications_session_route_manager:*:*:*:*:*:*:*:*
oracle data_integrator 12.2.1.3.0 cpe:2.3:a:oracle:data_integrator:12.2.1.3.0:*:*:*:*:*:*:*
oracle data_integrator 12.2.1.4.0 cpe:2.3:a:oracle:data_integrator:12.2.1.4.0:*:*:*:*:*:*:*
oracle demantra_demand_management >= 12.2.6, <= 12.2.11 cpe:2.3:a:oracle:demantra_demand_management:*:*:*:*:*:*:*:*
oracle documaker >= 12.6.2, <= 12.6.4 cpe:2.3:a:oracle:documaker:*:*:*:*:*:*:*:*
oracle documaker 12.6.0 cpe:2.3:a:oracle:documaker:12.6.0:*:*:*:*:*:*:*

References for CVE-2021-2351

URL Tags
http://packetstormsecurity.com/files/165255/Oracle-Database-Protection-Mechanism-Bypass.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/165258/Oracle-Database-Weak-NNE-Integrity-Key-Derivation.html Exploit Third Party Advisory VDB Entry
http://seclists.org/fulldisclosure/2021/Dec/19 Exploit Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2021/Dec/20 Exploit Mailing List Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html Patch Vendor Advisory
https://www.oracle.com/security-alerts/cpujan2022.html Patch Vendor Advisory
https://www.oracle.com/security-alerts/cpujan2023.html Vendor Advisory
https://www.oracle.com/security-alerts/cpujul2021.html Patch Vendor Advisory
https://www.oracle.com/security-alerts/cpujul2022.html Vendor Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html Patch Vendor Advisory
cvelogic Threat Intelligence