PT-2026-71654 · Rsync-Ssl+1 · Rsync-Ssl+1
CVSS v3.1
8.0
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
rsync versions 3.2.0 through 3.2.3
rsync-ssl versions prior to 3.4.5
Description
A TLS certificate validation issue allows on-path attackers to intercept encrypted sessions by presenting self-signed or invalid certificates. This occurs because the software fails to validate server TLS certificates against a trusted Certificate Authority (CA) or verify that the certificate hostname matches. Consequently, an attacker can decrypt or tamper with session content without the client detecting the interference.
Recommendations
Update rsync to version 3.5.0 or later.
Update rsync-ssl to version 3.4.5 or later.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rsync
Rsync-Ssl