CVE-2021-3716
—CVSS 3.1
3.1 low
EPSS
<1%p46
Published
()
Modified
Description
A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everything else a client sends to the server, potentially leading the client to terminate the NBD session. The highest threat from this vulnerability is to system availability.
- Vendors
- nbdkit projectredhat
- Products
- nbdkit, enterprise linux
- Weakness
- CWE-924
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.