Security readout for executives and security teams
Plain-English summary
CVE-2021-35621 affects Oracle MySQL Cluster. An attacker who already has high privileges and access to the physical communication segment for the cluster could, with user interaction, take over the cluster. The business impact is serious for exposed clusters, but exploitation conditions are restrictive.
Executive priority
Treat this as a scheduled but important remediation for MySQL Cluster environments. Prioritize faster where the cluster supports critical services or where privileged access to the cluster network is broadly available.
Technical view
The issue is in MySQL Cluster, component Cluster: General, affecting 7.4.33 and prior, 7.5.23 and prior, 7.6.19 and prior, and 8.0.26 and prior. CVSS 3.1 is 6.3 with adjacent access, high complexity, high privileges, required user interaction, and high confidentiality, integrity, and availability impact.
Likely exposure
Exposure is likely limited to organizations running affected MySQL Cluster versions where highly privileged users or systems can access the physical communication segment attached to the cluster hardware.
Exploitation context
The provided sources do not show active exploitation, and the CVE is not marked KEV. Exploitation is described as difficult and requires high privileges, adjacent/physical-segment access, and human interaction by someone other than the attacker.
Researcher notes
No CWE is provided in the source bundle. The strongest practical constraints are AV:A, AC:H, PR:H, and UI:R. Do not assume internet-reachable exploitation from the supplied evidence. Use Oracle and ZDI advisories for vendor-grounded technical context.
Mitigation direction
- Review Oracle October 2021 CPU guidance for the applicable MySQL Cluster update.
- Upgrade affected MySQL Cluster versions beyond the listed vulnerable releases.
- Restrict access to the cluster communication segment to trusted administrative paths.
- Check NetApp guidance if MySQL Cluster is present through NetApp-supported products.
Validation and detection
- Inventory all MySQL Cluster deployments and record exact versions.
- Flag versions 7.4.33, 7.5.23, 7.6.19, 8.0.26, and earlier.
- Verify who can access the physical cluster communication segment.
- Confirm vendor patch or advisory status from Oracle and relevant downstream vendors.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-35621 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 6.3 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H0.45.9Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
6.3MediumVector: CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Source materials
- CVE List V5 sourceCVE List V5
- https://www.oracle.com/security-alerts/cpuoct2021.htmlCVE reference · x_refsource_MISC
- https://www.zerodayinitiative.com/advisories/ZDI-21-1232/CVE reference · x_refsource_MISC
- https://security.netapp.com/advisory/ntap-20211022-0003/CVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
