Man-in-the-Middle (MitM) attack in Exim - CVE-2021-38371
Published: March 20, 2023
Vulnerability identifier: #VU73857
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-38371
CWE-ID: CWE-300
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to the way Exim handles concurrent STARTTLS sessions when sending out emails. A malicious server can send a response to the *next* command within the existing STARTTLS sessions and force the Exim to treat this session as trusted.
Affected software
Exim
Amazon Linux AMI
Fedora
Ubuntu
SmartFabric Storage Software
exim4 (Ubuntu package)
exim4-base (Ubuntu package)
eximon4 (Ubuntu package)
exim
Amazon Linux AMI
Fedora
Ubuntu
SmartFabric Storage Software
exim4 (Ubuntu package)
exim4-base (Ubuntu package)
eximon4 (Ubuntu package)
exim
How to mitigate CVE-2021-38371
Install updates from vendor's website.
Exim - update to 4.95
SmartFabric Storage Software - update to 1.4.3
exim4 (Ubuntu package) - addressed in versions Ubuntu Pro, 4.93-13ubuntu1.11
exim4-base (Ubuntu package) - addressed in versions Ubuntu Pro, 4.93-13ubuntu1.11
eximon4 (Ubuntu package) - addressed in versions Ubuntu Pro, 4.93-13ubuntu1.11
exim - update to 4.92-1.36
exim - update to 4.95-1.el8
SmartFabric Storage Software - update to 1.4.3
exim4 (Ubuntu package) - addressed in versions Ubuntu Pro, 4.93-13ubuntu1.11
exim4-base (Ubuntu package) - addressed in versions Ubuntu Pro, 4.93-13ubuntu1.11
eximon4 (Ubuntu package) - addressed in versions Ubuntu Pro, 4.93-13ubuntu1.11
exim - update to 4.92-1.36
exim - update to 4.95-1.el8