« Volver al listado

CVE-2020-14387

Estado: ModificadaAlta (7.4)—

A flaw was found in rsync in versions since 3.2.0pre1. Rsync improperly validates certificate with host mismatch vulnerability. A remote, unauthenticated attacker could exploit the flaw by performing a man-in-the-middle attack using a valid certificate for another hostname which could compromise confidentiality and integrity of data transmitted using rsync-ssl. The highest threat from this vulnerability is to data confidentiality and integrity. This flaw affects rsync versions before 3.2.4.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-14387",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.4,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "rsync",
          "versions": [
            {
              "status": "affected",
              "version": "rsync 3.2.4"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-05-27T20:15:07.873",
  "references": [
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1875549",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1875549",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-297"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A flaw was found in rsync in versions since 3.2.0pre1. Rsync improperly validates certificate with host mismatch vulnerability. A remote, unauthenticated attacker could exploit the flaw by performing a man-in-the-middle attack using a valid certificate for another hostname which could compromise confidentiality and integrity of data transmitted using rsync-ssl. The highest threat from this vulnerability is to data confidentiality and integrity. This flaw affects rsync versions before 3.2.4."
    },
    {
      "lang": "es",
      "value": "Se encontró un fallo en rsync en versiones desde 3.2.0pre1. Rsync comprueba inapropiadamente el certificado con vulnerabilidad de discrepancia de host. Un atacante remoto no autenticado podría explotar el fallo llevando a cabo un de tipo ataque de tipo man-in-the-middle usando un certificado válido para otro nombre de host que podría comprometer la confidencialidad e integridad de los datos transmitidos usando rsync-ssl. La mayor amenaza de esta vulnerabilidad es la confidencialidad e integridad de los datos. Este fallo afecta a rsync versiones anteriores a 3.2.4"
    }
  ],
  "lastModified": "2026-06-17T02:54:40.573",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:samba:rsync:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "45922B1C-D968-46DD-8EE6-F0B22F085733",
              "versionEndExcluding": "3.2.4",
              "versionStartIncluding": "3.2.1"
            },
            {
              "criteria": "cpe:2.3:a:samba:rsync:3.2.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E3E08234-5E6E-444D-B466-7FDADB951199"
            },
            {
              "criteria": "cpe:2.3:a:samba:rsync:3.2.0:pre1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D3FA9537-95CA-4B6D-8162-6DC5D4B0BD32"
            },
            {
              "criteria": "cpe:2.3:a:samba:rsync:3.2.0:pre2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "06F27E32-CB3F-4140-AFBD-1A65031D42F5"
            },
            {
              "criteria": "cpe:2.3:a:samba:rsync:3.2.0:pre3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5EB9157B-D013-400A-A5F3-8088676586C8"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}