CVE-2021-45100
The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even though encryption has been enabled.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.91%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even though encryption has been enabled. This occurs because it sets the SMB2_GLOBAL_CAP_ENCRYPTION flag when using the SMB 3.1.1 protocol, which is a violation of the SMB protocol specification. When Windows 10 detects this protocol violation, it disables encryption.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.91% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-319
- Affected
- ksmbd project/ksmbd · netapp/h410c firmware · netapp/h300s firmware · netapp/h500s firmware · netapp/h700s firmware · netapp/h300e firmware · netapp/h500e firmware · netapp/h700e firmware · netapp/h410s firmware
- Source
- cve@mitre.org
References
- https://github.com/cifsd-team/ksmbd/issues/550Third Party Advisory
- https://github.com/cifsd-team/ksmbd/pull/551Patch, Third Party Advisory
- https://marc.info/?l=linux-kernel&m=163961726017023&w=2Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220107-0001/Third Party Advisory
- https://github.com/cifsd-team/ksmbd/issues/550Third Party Advisory
- https://github.com/cifsd-team/ksmbd/pull/551Patch, Third Party Advisory
- https://marc.info/?l=linux-kernel&m=163961726017023&w=2Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220107-0001/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.