← Voltar para CVEs
CVE-2021-44273
HIGH7.4
Descricao
e2guardian v5.4.x <= v5.4.3r is affected by missing SSL certificate validation in the SSL MITM engine. In standalone mode (i.e., acting as a proxy or a transparent proxy), with SSL MITM enabled, e2guardian, if built with OpenSSL v1.1.x, did not validate hostnames in certificates of the web servers that it connected to, and thus was itself vulnerable to MITM attacks.
Detalhes CVE
Pontuacao CVSS v3.17.4
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Vetor de ataqueNETWORK
ComplexidadeHIGH
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado12/23/2021
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0
Produtos afetados
e2bn:e2guardian
Fraquezas (CWE)
CWE-295
Referencias
http://www.openwall.com/lists/oss-security/2021/12/23/2(cve@mitre.org)
https://github.com/e2guardian/e2guardian/commit/eae46a7e2a57103aadca903c4a24cca94dc502a2(cve@mitre.org)
https://github.com/e2guardian/e2guardian/issues/707(cve@mitre.org)
http://www.openwall.com/lists/oss-security/2021/12/23/2(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/e2guardian/e2guardian/commit/eae46a7e2a57103aadca903c4a24cca94dc502a2(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/e2guardian/e2guardian/issues/707(af854a3a-2127-422b-91ae-364da2661108)
https://lists.debian.org/debian-lts-announce/2023/09/msg00010.html(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.