Vulnerability Description
An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked nor displayed. As a result, a user connects to the server without the ability to verify its authenticity.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Midnight-Commander | Midnight Commander | <= 4.8.26 |
Related Weaknesses (CWE)
References
- https://docs.ssh-mitm.at/CVE-2021-36370.htmlExploitThird Party Advisory
- https://github.com/MidnightCommander/mc/blob/5c1d3c55dd15356ec7d079084d904b7b0fdExploitThird Party Advisory
- https://github.com/MidnightCommander/mc/blob/master/src/vfs/sftpfs/connection.cExploitThird Party Advisory
- https://mail.gnome.org/archives/mc-devel/2021-August/msg00008.htmlRelease NotesThird Party Advisory
- https://midnight-commander.org/Vendor Advisory
- https://sourceforge.net/projects/mcwin32/files/ProductThird Party Advisory
- https://docs.ssh-mitm.at/CVE-2021-36370.htmlExploitThird Party Advisory
- https://github.com/MidnightCommander/mc/blob/5c1d3c55dd15356ec7d079084d904b7b0fdExploitThird Party Advisory
- https://github.com/MidnightCommander/mc/blob/master/src/vfs/sftpfs/connection.cExploitThird Party Advisory
- https://mail.gnome.org/archives/mc-devel/2021-August/msg00008.htmlRelease NotesThird Party Advisory
- https://midnight-commander.org/Vendor Advisory
- https://sourceforge.net/projects/mcwin32/files/ProductThird Party Advisory
FAQ
What is CVE-2021-36370?
CVE-2021-36370 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked nor displayed. As a result, a user connects to the ...
How severe is CVE-2021-36370?
CVE-2021-36370 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-36370?
Check the references section above for vendor advisories and patch information. Affected products include: Midnight-Commander Midnight Commander.