CVE-2021-45100
Last modified
CVE-2021-45100 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even though encryption has been enabled. This occurs because it sets the SMB2_GLOBAL_CAP_ENCRYPTION flag when using the SMB 3.1.1 protocol, which is a violation of the SMB protocol specification. EPSS estimates a 0.91% chance of exploitation in the next 30 days.
Description
The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even though encryption has been enabled. This occurs because it sets the SMB2_GLOBAL_CAP_ENCRYPTION flag when using the SMB 3.1.1 protocol, which is a violation of the SMB protocol specification. When Windows 10 detects this protocol violation, it disables encryption.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ksmbd Project | Ksmbd | <= 3.4.2 |
| Netapp | H410c Firmware | All versions |
| Netapp | H300s Firmware | All versions |
| Netapp | H500s Firmware | All versions |
| Netapp | H700s Firmware | All versions |
| Netapp | H300e Firmware | All versions |
| Netapp | H500e Firmware | All versions |
| Netapp | H700e Firmware | All versions |
| Netapp | H410s Firmware | All versions |
References
- https://github.com/cifsd-team/ksmbd/issues/550Third Party Advisory
- https://github.com/cifsd-team/ksmbd/pull/551Patch, Third Party Advisory
- https://marc.info/?l=linux-kernel&m=163961726017023&w=2Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220107-0001/Third Party Advisory
- https://github.com/cifsd-team/ksmbd/issues/550Third Party Advisory
- https://github.com/cifsd-team/ksmbd/pull/551Patch, Third Party Advisory
- https://marc.info/?l=linux-kernel&m=163961726017023&w=2Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220107-0001/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-45100?
How severe is CVE-2021-45100?
How do I fix CVE-2021-45100?
Are you affected by CVE-2021-45100?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
