9.8
CVSSv3

CVE-2019-15522

Published: 20/03/2020 Updated: 14/10/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in LINBIT csync2 up to and including 2.0. csync_daemon_session in daemon.c neglects to force a failure of a hello command when the configuration requires use of SSL.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linbit csync2

Vendor Advisories

Debian Bug report logs - #955445 CVE-2019-15522 Package: csync2; Maintainer for csync2 is Debian HA Maintainers <debian-ha-maintainers@listsaliothdebianorg>; Source for csync2 is src:csync2 (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 31 Mar 2020 20:27:04 UTC Severity: importa ...