CVE Vulnerabilities

CVE-2021-36370

Improper Authentication

Published: Aug 30, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked nor displayed. As a result, a user connects to the server without the ability to verify its authenticity.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Midnight_commanderMidnight-commander*4.8.26 (including)
McUbuntubionic*
McUbuntuesm-apps/bionic*
McUbuntuesm-apps/focal*
McUbuntuesm-apps/jammy*
McUbuntuesm-apps/xenial*
McUbuntuesm-infra-legacy/trusty*
McUbuntufocal*
McUbuntuhirsute*
McUbuntuimpish*
McUbuntujammy*
McUbuntutrusty*
McUbuntutrusty/esm*
McUbuntuupstream*
McUbuntuxenial*

Potential Mitigations

References