Impact
BusyBox httpd interprets IP deny rules that contain invalid CIDR prefix lengths incorrectly, causing the parser to fail open and leave the mask zeroed. The rule then matches no clients, effectively removing the intended block and allowing any IP address to reach the service. This exposure creates a direct access control bypass for any endpoint protected only by such rules, potentially revealing sensitive functionality or data to unauthorized users.
Affected Systems
The flaw is present in Red Hat Hardened Images that include the BusyBox httpd component, specifically the Hummingbird 1 image identified by the CPE cpe:/a:redhat:hummingbird:1. All installations using this image without an update that fixes the parsing bug are affected; no additional vendor product versions are listed as impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity vulnerability. The EPSS score is not available, so there is no quantified exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The issue is a failed denial‑rule implementation that can be exploited by any user who can reach the service, but it does not provide remote code execution or privilege escalation. The risk remains moderate, primarily affecting the confidentiality and integrity of the protected service.
OpenCVE Enrichment