CVE-2026-70454
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-295
Validación incorrecta de certificados
Fecha de publicación:
13/08/2026
Última modificación:
13/08/2026
Descripción
*** Pendiente de traducción *** rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to validate server TLS certificates against a trusted CA or verify certificate hostname matching to decrypt or tamper with rsync session content without detection by the client.
Impacto
Puntuación base 4.0
7.60
Gravedad 4.0
ALTA
Puntuación base 3.x
8.00
Gravedad 3.x
ALTA



