Impact
The vulnerability in rsync versions older than 3.5.0 causes the client to fail to validate TLS certificates presented in openssl and stunnel mode. An attacker on the network can supply a self‑signed or otherwise invalid certificate, enabling the bypass of certificate checking. This allows the attacker to decrypt or tamper with rsync data transferred between client and server. The weakness is classified as CWE‑295 and results in a compromise of confidentiality and integrity of the transferred data.
Affected Systems
Vendors: RsyncProject – rsync. Affected releases include rsync 3.2.0 through 3.2.3 when built with openssl mode and rsync‑ssl 3.4.4 when running in stunnel mode. Any deployments of these specific or earlier releases that use encrypted transfers are susceptible.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity. EPSS data is not available, and the vulnerability is not listed in the KEV catalog, suggesting no known active exploitation. The likely attack vector is a network‑based, on‑path attacker who can intercept rsync traffic and present a forged TLS certificate. Exploitation requires no additional privileges but results in exposure of sensitive data transferred over rsync sessions. The risk is elevated for environments that rely on this insecure mode for confidentiality.
OpenCVE Enrichment