PatchSiren cyber security CVE debrief
CVE-2021-27852 Checkbox CVE debrief
CVE-2021-27852 is a Checkbox Survey deserialization of untrusted data vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-04-11, which makes this a high-priority remediation item for any organization still using the product.
- Vendor
- Checkbox
- Product
- Checkbox Survey
- CVSS
- CRITICAL 9.8
- CISA KEV
- Listed
- Original CVE published
- 2022-04-11
- Original CVE updated
- 2022-04-11
- Advisory published
- 2022-04-11
- Advisory updated
- 2022-04-11
Who should care
Organizations that use Checkbox Survey, especially any environments still running version 6 or earlier. CISA states versions 6 and earlier are end-of-life and must be removed from agency networks; versions 7 and later are not considered vulnerable.
Technical summary
The issue is described as deserialization of untrusted data in Checkbox Survey. The supplied sources do not provide a CVSS score or deeper technical specifics, so the safest defensive interpretation is to treat affected deployments as exposed until confirmed otherwise and follow CISA's version guidance.
Defensive priority
Urgent. This CVE is listed in CISA's Known Exploited Vulnerabilities catalog, and the supplied timeline includes a remediation due date of 2022-05-02. Remove version 6 and earlier from service and verify whether any remaining installs are version 7 or later.
Recommended defensive actions
- Inventory all Checkbox Survey deployments and identify the installed version.
- Remove all versions 6 and earlier from agency or enterprise networks as directed by CISA.
- Confirm that any remaining installations are version 7 or later, since CISA states those are not considered vulnerable.
- Prioritize remediation immediately because the vulnerability is KEV-listed and treated as actively exploited by CISA.
Evidence notes
The supplied CISA KEV metadata identifies the vendor as Checkbox, the product as Checkbox Survey, the vulnerability name as "Deserialization of Untrusted Data Vulnerability," dateAdded as 2022-04-11, and dueDate as 2022-05-02. CISA's requiredAction states: "Versions 6 and earlier for this product are end-of-life and must be removed from agency networks. Versions 7 and later are not considered vulnerable." The provided corpus does not include a CVSS score.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-27852 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-27852
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-27852 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-27852
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.