CVE-2021-44273

e2guardian v5.4.x <= v5.4.3r is affected by missing SSL certificate validation in the SSL MITM engine. In standalone mode (i.e., acting as a proxy or a transparent proxy), with SSL MITM enabled, e2guardian, if built with OpenSSL v1.1.x, did not validate hostnames in certificates of the web servers that it connected to, and thus was itself vulnerable to MITM attacks.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.4 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 41%
VendorProductVersion
e2bne2guardian
5.4.0 ≤
𝑥
≤ 5.4.3r
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
e2guardian
bullseye
5.3.4-1+deb11u1
fixed
stretch
ignored
bookworm
5.3.5-4
fixed
trixie
5.5.5-1
fixed
sid
5.5.6-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
e2guardian
noble
needs-triage
mantic
ignored
lunar
ignored
kinetic
ignored
jammy
needs-triage
impish
ignored
hirsute
ignored
focal
needs-triage
bionic
needs-triage
xenial
ignored
trusty
ignored