Man-in-the-Middle (MitM) attack in Exim - CVE-2021-38371

 

Man-in-the-Middle (MitM) attack in Exim - CVE-2021-38371

Published: March 20, 2023


Vulnerability identifier: #VU73857
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-38371
CWE-ID: CWE-300
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to the way Exim handles concurrent STARTTLS sessions when sending out emails. A malicious server can send a response to the *next* command within the existing STARTTLS sessions and force the Exim to treat this session as trusted.


Affected software

Exim
Amazon Linux AMI
Fedora
Ubuntu
SmartFabric Storage Software
exim4 (Ubuntu package)
exim4-base (Ubuntu package)
eximon4 (Ubuntu package)
exim

How to mitigate CVE-2021-38371

Install updates from vendor's website.

Exim - update to 4.95
SmartFabric Storage Software - update to 1.4.3
exim4 (Ubuntu package) - addressed in versions Ubuntu Pro, 4.93-13ubuntu1.11
exim4-base (Ubuntu package) - addressed in versions Ubuntu Pro, 4.93-13ubuntu1.11
eximon4 (Ubuntu package) - addressed in versions Ubuntu Pro, 4.93-13ubuntu1.11
exim - update to 4.92-1.36
exim - update to 4.95-1.el8

External References

Related Security Bulletins