ZeroHour

CVE-2021-45100

CVSS 3.1
7.5 high
EPSS
<1%p58
Published
()
Modified
Description

The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even though encryption has been enabled. This occurs because it sets the SMB2_GLOBAL_CAP_ENCRYPTION flag when using the SMB 3.1.1 protocol, which is a violation of the SMB protocol specification. When Windows 10 detects this protocol violation, it disables encryption.

Vendors
ksmbd projectnetapp
Products
ksmbd, h410c firmware, h300s firmware, h500s firmware, h700s firmware, h300e firmware, h500e firmware, h700e firmware, h410s firmware
Weakness
CWE-319
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.