An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked nor displayed. As a result, a user connects to the server without the ability to verify its authenticity.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade mcUpgrade mc-debuginfo | Jul 21, 2023 | Aug 30, 2021 |
| Debian | — | Upgrade mc | Jul 30, 2024 | Aug 30, 2021 |
| Suse | — | Upgrade mcUpgrade mc-lang | Mar 2, 2022 | Aug 30, 2021 |
| Ubuntu | — | Upgrade mc-data (Ubuntu Pro)Upgrade mc (Ubuntu Pro) | Mar 22, 2023 | Aug 30, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Feb 9, 2026 | Aug 30, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub