Vulnerability record · CVE-2021-35621 · published 20 October 2021
CVE-2021-35621: Oracle MySQL Cluster general component flaw allows takeover
Oracle · Mysql Cluster
A vulnerability in the general component of Oracle MySQL Cluster affects versions 7.4.33, 7.5.23, 7.6.19 and 8.0.26 and prior. It is difficult to exploit but can let a high-privileged attacker with access to the physical communication segment take over the cluster, with high confidentiality, integrity and availability impact.
Description
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.33 and prior, 7.5.23 and prior, 7.6.19 and prior and 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Automated analysis
medium priorityCVSS 6.3 medium with high EPSS but exploitation needs adjacent access, high privileges and user interaction, and no KEV or public exploit is recorded.
What it is
A vulnerability in the general component of Oracle MySQL Cluster affects versions 7.4.33, 7.5.23, 7.6.19 and 8.0.26 and prior. It is difficult to exploit but can let a high-privileged attacker with access to the physical communication segment take over the cluster, with high confidentiality, integrity and availability impact.
Impact
An attacker who succeeds gains full takeover of the MySQL Cluster, affecting confidentiality, integrity and availability of the cluster data and services.
Attack surface
Reached over the adjacent physical communication segment (AV:A) and requires high privileges (PR:H) plus human interaction from another person (UI:R). No remote network vector and no unauthenticated path are described.
Exploitation
Not listed in CISA KEV and no ransomware use documented; EPSS is high at roughly 0.50 (98.8th percentile), but references are only vendor and third-party advisories with no public exploit tag.
What to do
- Apply the Oracle October 2021 CPU fixes for MySQL Cluster (7.4.33, 7.5.23, 7.6.19, 8.0.26 and later) and the NetApp advisories for affected products.
- Restrict physical and adjacent-network access to cluster nodes and the communication segment to trusted, authorized personnel.
- Limit high-privilege cluster accounts and enforce least privilege to reduce the PR:H precondition.
- Monitor and control interactive sessions on cluster hosts to address the UI:R requirement.
Detection
- Audit cluster node access logs for unexpected high-privileged sessions or interactive activity on the communication segment.
- Monitor for abnormal cluster state changes, configuration edits or service restarts consistent with takeover attempts.
- Track patch levels of MySQL Cluster and NetApp products against the fixed versions and alert on unpatched nodes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://security.netapp.com/advisory/ntap-20211022-0003/ | Third Party Advisory |
| https://www.oracle.com/security-alerts/cpuoct2021.html | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-1232/ | Third Party AdvisoryVDB Entry |
| https://security.netapp.com/advisory/ntap-20211022-0003/ | Third Party Advisory |
| https://www.oracle.com/security-alerts/cpuoct2021.html | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-1232/ | Third Party AdvisoryVDB Entry |
Track CVE-2021-35621 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-35621), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.