CVE-2020-14387Improper Validation of Certificate with Host Mismatch in Samba Rsync

Severity
7.4HIGHNVD
EPSS
0.1%
top 65.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 27
Latest updateMay 24

Description

A flaw was found in rsync in versions since 3.2.0pre1. Rsync improperly validates certificate with host mismatch vulnerability. A remote, unauthenticated attacker could exploit the flaw by performing a man-in-the-middle attack using a valid certificate for another hostname which could compromise confidentiality and integrity of data transmitted using rsync-ssl. The highest threat from this vulnerability is to data confidentiality and integrity. This flaw affects rsync versions before 3.2.4.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 2.2 | Impact: 5.2

Affected Packages3 packages

NVDsamba/rsync3.2.13.2.4+1
Debiansamba/rsync< 3.2.3-3+3
CVEListV5samba/rsyncrsync 3.2.4

Patches

🔴Vulnerability Details

3
GHSA
GHSA-5gm2-c485-9q6q: A flaw was found in rsync in versions since 32022-05-24
CVEList
CVE-2020-14387: A flaw was found in rsync in versions since 32021-05-27
OSV
CVE-2020-14387: A flaw was found in rsync in versions since 32021-05-27

📋Vendor Advisories

3
Microsoft
A flaw was found in rsync in versions since 3.2.0pre1. Rsync improperly validates certificate with host mismatch vulnerability. A remote unauthenticated attacker could exploit the flaw by performing a2021-05-11
Red Hat
rsync: rsync-ssl does not verify the hostname in the server certificate when using openssl2020-09-03
Debian
CVE-2020-14387: rsync - A flaw was found in rsync in versions since 3.2.0pre1. Rsync improperly validate...2020

💬Community

2
Bugzilla
CVE-2020-14387 rsync: rsync-ssl does not verify the hostname in the server certificate when using openssl2020-09-03
Bugzilla
CVE-2020-14387 rsync: rsync-ssl does not verify the hostname in the server certificate when using openssl [fedora-32]2020-09-03