CVE-2021-3156General(beyondtrust / active_iq_unified_manager)

MEDIUMCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch beyondtrust active_iq_unified_manager systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

5.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-04-27. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-193

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • active_iq_unified_manager
  • cloud_backup
  • communications_performance_intelligence_center
  • debian_linux

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 17 mentions across 16 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • General: 14 classified signals
  • Peaked 14d ago at 2 mentions (2026-02-12); latest day: 1
  • 17 total mentions across 16 days

Affected systems

Products
active_iq_unified_managercloud_backupcommunications_performance_intelligence_centerdebian_linuxdiskstation_managerdiskstation_manager_unified_controllerfedorahci_management_nodemicros_compact_workstation_3micros_compact_workstation_3_firmware

15 versions affected across 31 products

Deep dive

Activity timeline17 mentions / 16d
01122Mentions · 2026-02-09: 1Mentions · 2026-02-12: 2Mentions · 2026-02-17: 1Mentions · 2026-02-25: 1Mentions · 2026-02-27: 1Mentions · 2026-03-12: 1Mentions · 2026-03-21: 1Mentions · 2026-03-29: 1Mentions · 2026-04-03: 1Mentions · 2026-04-06: 1Mentions · 2026-04-25: 1Mentions · 2026-05-01: 1Mentions · 2026-05-02: 1Mentions · 2026-06-05: 1Mentions · 2026-06-30: 1Mentions · 2026-07-27: 1Active Exploitation · 2026-02-09: 1Patch / Workaround · 2026-05-01: 1Technical Details · 2026-02-12: 1Technical Details · 2026-06-05: 1Technical Details · 2026-06-30: 1Technical Details · 2026-07-27: 102-0902-1202-1702-2502-2703-1203-2103-2904-0304-0604-2505-0105-0206-0506-3007-27
Signal classification4 categories
General
1482.4%
Active Exploitation
15.9%
Patch
15.9%
Disclosure
15.9%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-091
Active Exploitation1
2026-02-122
General2
2026-02-171
General1
2026-02-251
General1
2026-02-271
General1
2026-03-121
General1
2026-03-211
General1
2026-03-291
General1
2026-04-031
General1
2026-04-061
General1
2026-04-251
General1
2026-05-011
Patch1
2026-05-021
General1
2026-06-051
General1
2026-06-301
General1
2026-07-271
Disclosure1
Full discourse17 posts
  • Saша Stark 🔲 Zero to Null MRR 🔳 swe/av/acc@tsybalab
    General

    @0xrinx No, for example 3 of them with 1 editor all like a lot Vim CVE-2019-12735 Snap CVE-2021-3156 Kernel CVE-2016-5195 @grok verify ✔️

    Post summary

    The passage merely enumerates a few CVE identifiers without providing any supporting technical details, evidence of exploitation, or mitigation information.

    2011034
    432 followersView on X
  • ExploitGrid@exploitgrid
    Disclosure

    On this day, CVE-2021-3156: Baron Samedit, came to light. A heap overflow bug sat in sudo for nearly a decade before anyone found it, giving local users a path to root on most Linux systems. #CVE #LinuxSecurity

    Post summary

    The statement announces the discovery of CVE‑2021‑3156 (Baron Samedit), a heap‑overflow bug in sudo that allows local privilege escalation, but offers no PoC, exploit, patch, or evidence of active use.

    0101024
    28 followersView on X
  • Aristarchus of Samos@AristoSamos
    General

    @tibfulv @LundukeJournal Sudo had a catastrophic heap buffer overflow (CVE-2021-3156) hiding in its "battle-tested" C code for 10 years before discovery. It granted instant root. C doesn't stop hiding zero-days just because it's old. Rust stops them at compile. But this is a healthy discussion.

    Post summary

    The tweet briefly highlights the CVE‑2021‑3156 heap overflow in sudo, noting its severity but providing no PoC, tool, or exploitation details.

    1001046
    363 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-31431 2 - CVE-2021-3156 3 - CVE-2025-14847 4 - CVE-2024-27867 5 - CVE-2024-11182 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists trending CVE identifiers without providing any technical, patch, or exploit details.

    000111.0K
    1.7K followersView on X
  • Mohi@disismohi
    General

    The dataset: CVE-2021-3156 (sudo heap overflow), CVE-2022-0847 (Dirty Pipe), CVE-2023-38545 (curl SOCKS5). Real vulnerable functions from OpenSSL, Linux kernel, cURL.

    Post summary

    The text lists three CVEs—CVE-2021-3156, CVE-2022-0847, CVE-2023-38545—and identifies their associated vulnerable functions or components (sudo, Linux kernel, curl).

    1000047
    63 followersView on X
  • Syn Marnotrawny 🇵🇱@th_prodigal_son
    Patch

    @ljachowicz . wszystko tu można wymyślić ale sam widzisz ilości stwierdzeń warunkowych, a ja mam na myśli jedynie fakt, żeby być w miarę precyzyjnym w naganianiu tej paniki… to lokalna klapa porównywalna w skutkach do CVE-2021-3156 albo CVE-2025-32462/CVE-2025-32463 i wystarczy zpatchować

    Post summary

    The post mentions a local flaw comparable to known CVEs and asserts that patching is sufficient, yet it provides no explicit patch details or exploit discussion.

    00001891
    1.8K followersView on X
  • Saша Stark 🔲 Zero to Null MRR 🔳 swe/av/acc@tsybalab
    General

    @DsplayNam3 @CR1337 Oh seriously. Linux hacked also but in other sophisticated way f.e. 3 of them with 1 editor all like a lot Vim CVE-2019-12735 Snap CVE-2021-3156 Kernel CVE-2016-5195 @grok verify ✔️

    Post summary

    The post lists several CVEs but provides no additional context, technical details, or actionable information.

    10000205
    439 followersView on X
  • Jayesh Verma@JayeshV88153533
    General

    I just completed Baron Samedit room on TryHackMe! A tutorial room exploring CVE-2021-3156 in the Unix Sudo Program. Room Three in the SudoVulns Series https://tryhackme.com/room/sudovulnssamedit?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=684d724b80fe1af75347f3e4 #tryhackme via @tryhackme

    Post summary

    The user completed a TryHackMe tutorial room that covers CVE-2021-3156 in the Unix Sudo program, but no PoC, exploit, patch, or detailed technical information is provided.

    0001031
    16 followersView on X
  • ~Johann@Johan_hyuga
    Active Exploitation

    En una agencia digital de 20 empleados en España, un servidor Linux (Debian 10) sin parches durante 9 meses permitió un exploit simple (CVE-2021-3156 en sudo). Resultado: datos cifrados, 4 días offline, pérdida de +12.000 € en ventas y recuperación.

    Post summary

    A Spanish digital agency’s unpatched Debian 10 server was exploited via CVE‑2021‑3156, resulting in data encryption, four days of downtime, and over €12,000 in lost sales.

    1000073
    297 followersView on X
  • 無重力トレーニング@acupunc28094787
    General

    I just completed Baron Samedit room on TryHackMe! A tutorial room exploring CVE-2021-3156 in the Unix Sudo Program. Room Three in the SudoVulns Series https://tryhackme.com/room/sudovulnssamedit?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=65869e2abbbd1398b6caad7d #tryhackme via @tryhackme

    Post summary

    The tweet reports completion of a TryHackMe tutorial room focused on CVE-2021-3156; it does not provide technical details, exploits, or patch information.

    0000031
    95 followersView on X
  • Sun4lower@LittleSun4lower
    General

    I just completed Baron Samedit room on TryHackMe! A tutorial room exploring CVE-2021-3156 in the Unix Sudo Program. Room Three in the SudoVulns Series https://tryhackme.com/room/sudovulnssamedit?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=66457951599dd28bfb000ded #tryhackme via @tryhackme #tryhackme #learning #Consistency

    Post summary

    The tweet notes the completion of a TryHackMe tutorial room on CVE-2021-3156, focusing on learning about the vulnerability without mentioning PoCs, exploits, patches, or detailed technical aspects.

    0000038
    5 followersView on X
  • VibeQuest@BaraniBr443638
    General

    I just completed Baron Samedit room on TryHackMe! A tutorial room exploring CVE-2021-3156 in the Unix Sudo Program. Room Three in the SudoVulns Series https://tryhackme.com/room/sudovulnssamedit?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=61eac99b5af18f0042650fad #tryhackme via @tryhackme

    Post summary

    User reports completing a TryHackMe tutorial room that explores CVE-2021-3156 in Unix Sudo, without providing detailed exploit, patch, or technical information.

    0000032
    6 followersView on X
  • 317ON13_LIRW@ToTo13ru_xakep
    General

    I just completed Baron Samedit room on TryHackMe! A tutorial room exploring CVE-2021-3156 in the Unix Sudo Program. Room Three in the SudoVulns Series https://tryhackme.com/room/sudovulnssamedit?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=662fb6411f3680a87baf9e1f #tryhackme via @tryhackme

    Post summary

    The tweet announces completion of a TryHackMe tutorial room covering CVE‑2021‑3156, without providing PoC details, exploit code, or mitigation information.

    0000022
  • Aurore IT@AureBK19
    General

    I just completed Baron Samedit room on TryHackMe! A tutorial room exploring CVE-2021-3156 in the Unix Sudo Program. Room Three in the SudoVulns Series https://tryhackme.com/room/sudovulnssamedit?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=688bed36673ef8570ab2dc8b #tryhackme via @tryhackme

    Post summary

    The tweet announces completion of a TryHackMe tutorial room focused on CVE-2021-3156, but it does not provide explicit PoC, exploit details, or other actionable information.

    0000034
    3 followersView on X
  • fichwgrk@grokfc755
    General

    @grok What is CVE-2021-3156 (Baron Samedit) sudo vulnerability? (respond in fun mode).

    Post summary

    The message is a straightforward question asking for an explanation of CVE-2021-3156, without supplying any technical details or additional information.

    0000022
    5 followersView on X
  • GREEN ARMOR | الدرع الأخضر@GREENARM0R
    General

    ⚠️ مجرد وجود SUID على sudo أو passwd طبيعي جدًا، الخطر غالبًا يكون في برامج غير معروفة/"الاعدادات الخاطئة misconfiguration" مثل ثغرة CVE-2021-3156 في sudo. 🔥اشترك الان الدورات الاحترافية عبر اكاديمية الدرع الأخضر 👇🏻 https://greenarmor.academy

    Post summary

    The post merely notes that CVE‑2021‑3156 is a vulnerability in sudo, without providing any further technical, exploit, or mitigation information.

    00000272
    30.1K followersView on X
  • Grok@grok
    General

    Verified ✔️ - CVE-2019-12735: Vim vulnerability allowing arbitrary code execution via modelines (2019). - CVE-2021-3156: Sudo heap buffer overflow enabling privilege escalation (2021; note: associated with sudo, not Snap directly). - CVE-2016-5195: Linux kernel race condition (Dirty COW) for privilege escalation (2016). For context, Notepad's recent issue is CVE-2026-20841 (RCE, 2026).

    Post summary

    The text provides a brief list of several CVEs with minimal technical details, without indicating exploitation, PoC, patch, or false positive information.

    0000058
    8.1M followersView on X
CPE platform detail37 entries

37 of 37 entries

PartVendorProductVersionTarget SWTarget HW
Appbeyondtrustprivilege_management_for_mac---
Appbeyondtrustprivilege_management_for_unix\/linux---
OSdebiandebian_linux10.0--
OSdebiandebian_linux9.0--
OSfedoraprojectfedora32--
OSfedoraprojectfedora33--
Appmcafeeweb_gateway10.0.4--
Appmcafeeweb_gateway8.2.17--
Appmcafeeweb_gateway9.2.8--
Appnetappactive_iq_unified_manager-vmware_vsphere-
Appnetappcloud_backup---
Appnetapphci_management_node---
Appnetapponcommand_unified_manager_core_package---
Appnetappontap_select_deploy_administration_utility---
Appnetappontap_tools9vmware_vsphere-
Appnetappsolidfire---
Apporaclecommunications_performance_intelligence_center---
HWoraclemicros_compact_workstation_3---
OSoraclemicros_compact_workstation_3_firmware310--
HWoraclemicros_es400---
OSoraclemicros_es400_firmware---
HWoraclemicros_kitchen_display_system---
OSoraclemicros_kitchen_display_system_firmware210--
HWoraclemicros_workstation_5a---
OSoraclemicros_workstation_5a_firmware5a--
HWoraclemicros_workstation_6---
OSoraclemicros_workstation_6_firmware---
Apporacletekelec_platform_distribution---
Appsudo_projectsudo---
Appsudo_projectsudo1.9.5--
Appsudo_projectsudo1.9.5--
OSsynologydiskstation_manager6.2--
Appsynologydiskstation_manager_unified_controller3.0--
HWsynologyskynas---
OSsynologyskynas_firmware---
HWsynologyvs960hd---
OSsynologyvs960hd_firmware---

Explore more