CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2021-3733: python 3.10.0; +19 more affected products

CVE-2021-3733. CVSS 3.1 base score 6.5 (MEDIUM, NVD). EPSS 0.04675 (percentile 0.91534), scored 2026-10-08.

Affected technology

python · before 3.6.14 (exclusive)
python

python · from 3.7.0 (inclusive), before 3.7.11 (exclusive)
python

python · from 3.8.0 (inclusive), before 3.8.10 (exclusive)
python

python · from 3.9.0 (inclusive), before 3.9.5 (exclusive)
python

python · 3.10.0
python

codeready linux builder · 8.0
redhat

codeready linux builder for ibm z systems · 8.0
redhat

codeready linux builder for power little endian · 8.0
redhat

enterprise linux · 8.0
redhat

enterprise linux eus · 8.4
redhat

enterprise linux for ibm z systems · 8.0
redhat

enterprise linux for ibm z systems eus · 8.4
redhat

enterprise linux for power little endian · 8.0
redhat

enterprise linux for power little endian eus · 8.4
redhat

enterprise linux server aus · 8.4
redhat

enterprise linux server for power little endian update services for sap solutions · 8.4
redhat

enterprise linux server tus · 8.4
redhat

enterprise linux server update services for sap solutions · 8.4
redhat

extra packages for enterprise linux · 7.0
fedoraproject

fedora · 33
fedoraproject

fedora · 34
fedoraproject

fedora · 35
fedoraproject

fedora · 36
fedoraproject

management services for element software and netapp hci · Version not applicable in the source CPE
netapp

ontap select deploy administration utility · Version not applicable in the source CPE
netapp

solidfire, enterprise sds & hci storage node · Version not applicable in the source CPE
netapp

hci compute node firmware · Version not applicable in the source CPE
netapp

python · Fixed in python v3.6.14, python v3.7.11, python v3.8.10, python v3.9.5.
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (NVD, CVSS 3.1): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

The source reports that an attacker could disrupt service. NVD’s CVSS 3.1 assessment (base score 6.5/10) rates confidentiality and integrity impact as none; availability impact as high.

Published

CWE
CWE-400
CCR priority
27.2 /100 (P4)
CVSS 3.1
6.5 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H · NVD
EPSS
0.04675 · percentile 0.91534 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2021-3733.html