Impact
The rsync daemon before version 3.5.0 contains an IP address spoofing flaw that can be exploited by unauthenticated remote attackers. By sending a crafted PROXY protocol header with a forged source address, an attacker can bypass IP‑based access controls. The vulnerability stems from CWE‑290, which allows an attacker to forge source IP addresses and gain unauthorized access that would otherwise be blocked by host allow/deny rules.
Affected Systems
The affected product is rsync provided by the RsyncProject. All installations running rsync versions earlier than 3.5.0 are vulnerable. No specific sub‑versions are listed, so any release prior to 3.5.0 should be considered at risk.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity of the vulnerability. The EPSS score is not available, but the lack of KEX listing in the CISA KEV catalog suggests that publicly available exploits may not yet be widespread. Nevertheless, since the attack vector relies on an unauthenticated connection to the rsync daemon, the potential impact is significant. An attacker who can reach the daemon can inject a spoofed source IP into the PROXY protocol header, thereby circumventing IP‑based security controls and accessing data or performing actions with higher privileges than intended.
OpenCVE Enrichment