6.5

CVE-2021-3979

A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RedhatCeph Storage Version3.0
RedhatCeph Storage Version4.3
RedhatCeph Storage Version5.1
RedhatOpenstack Platform Version13.0
RedhatCeph Storage Version4.0
   RedhatEnterprise Linux Version8.0
RedhatCeph Storage Version5.0
   RedhatEnterprise Linux Version8.0
RedhatCeph Storage For Power Version4.0
   RedhatEnterprise Linux Version8.0
RedhatCeph Storage Version4.0
   RedhatEnterprise Linux Version7.0
RedhatCeph Storage Version5.0
   RedhatEnterprise Linux Version7.0
RedhatCeph Storage For Power Version4.0
   RedhatEnterprise Linux Version7.0
FedoraprojectFedora Version35
FedoraprojectFedora Version37
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.53
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

CWE-327 Use of a Broken or Risky Cryptographic Algorithm

The product uses a broken or risky cryptographic algorithm or protocol.