Vulnerability Details CVE-2020-12618
eM Client before 7.2.33412.0 automatically imported S/MIME certificates and thereby silently replaced existing ones. This allowed a man-in-the-middle attacker to obtain an email-validated S/MIME certificate from a trusted CA and replace the public key of the entity to be impersonated. This enabled the attacker to decipher further communication. The entire attack could be accomplished by sending a single email.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 32.5%
CVSS Severity
CVSS v3 Score 4.8
CVSS v2 Score 5.8
Products affected by CVE-2020-12618
-
cpe:2.3:a:emclient:em_client:1.0.2185.3
-
cpe:2.3:a:emclient:em_client:1.0.2188.1
-
cpe:2.3:a:emclient:em_client:1.0.2211.0
-
cpe:2.3:a:emclient:em_client:1.0.2266.0
-
cpe:2.3:a:emclient:em_client:1.0.2271.1
-
cpe:2.3:a:emclient:em_client:1.0.2273.0
-
cpe:2.3:a:emclient:em_client:1.0.2296.0
-
cpe:2.3:a:emclient:em_client:1.0.2304.0
-
cpe:2.3:a:emclient:em_client:1.0.2325.0
-
cpe:2.3:a:emclient:em_client:1.1.2379.3
-
cpe:2.3:a:emclient:em_client:1.1.2385.1
-
cpe:2.3:a:emclient:em_client:1.1.2418.0
-
cpe:2.3:a:emclient:em_client:1.1.2471.1
-
cpe:2.3:a:emclient:em_client:1.1.2600.0
-
cpe:2.3:a:emclient:em_client:1.1.2617.0
-
cpe:2.3:a:emclient:em_client:1.1.2665.0
-
cpe:2.3:a:emclient:em_client:1.1.2754.0
-
cpe:2.3:a:emclient:em_client:1.1.2816.0
-
cpe:2.3:a:emclient:em_client:1.1.2850.0
-
cpe:2.3:a:emclient:em_client:1.1.2876.0
-
cpe:2.3:a:emclient:em_client:1.1.2878.0
-
cpe:2.3:a:emclient:em_client:1.1.2888.0
-
cpe:2.3:a:emclient:em_client:1.1.2919.0
-
cpe:2.3:a:emclient:em_client:1.1.2958.0
-
cpe:2.3:a:emclient:em_client:1.1.3468.0
-
cpe:2.3:a:emclient:em_client:1.1.3469.0
-
cpe:2.3:a:emclient:em_client:1.1.3477.0
-
cpe:2.3:a:emclient:em_client:1.1.3487.0
-
cpe:2.3:a:emclient:em_client:1.1.3530.0
-
cpe:2.3:a:emclient:em_client:1.5.3789.0
-
cpe:2.3:a:emclient:em_client:1.5.3837.0
-
cpe:2.3:a:emclient:em_client:2.0.5036.0
-
cpe:2.3:a:emclient:em_client:2.0.5076.0
-
cpe:2.3:a:emclient:em_client:2.0.5109.0
-
cpe:2.3:a:emclient:em_client:2.0.5111.0
-
cpe:2.3:a:emclient:em_client:2.0.5144.0
-
cpe:2.3:a:emclient:em_client:2.0.5183.0
-
cpe:2.3:a:emclient:em_client:2.0.5510.0
-
cpe:2.3:a:emclient:em_client:2.0.5515.0
-
cpe:2.3:a:emclient:em_client:2.0.5579.0
-
cpe:2.3:a:emclient:em_client:2.0.5601.0
-
cpe:2.3:a:emclient:em_client:2.0.5604.0
-
cpe:2.3:a:emclient:em_client:2.0.5854.0
-
cpe:2.3:a:emclient:em_client:2.0.5952.0
-
cpe:2.3:a:emclient:em_client:2.0.6244.0
-
cpe:2.3:a:emclient:em_client:2.5.6362.0
-
cpe:2.3:a:emclient:em_client:2.5.6364.0
-
cpe:2.3:a:emclient:em_client:2.5.6375.0
-
cpe:2.3:a:emclient:em_client:2.5.6376.0
-
cpe:2.3:a:emclient:em_client:2.5.6388.0
-
cpe:2.3:a:emclient:em_client:2.5.6390.0
-
cpe:2.3:a:emclient:em_client:2.5.6396.0
-
cpe:2.3:a:emclient:em_client:2.5.6483.0
-
cpe:2.3:a:emclient:em_client:2.5.6495.0
-
cpe:2.3:a:emclient:em_client:2.5.6496.0
-
cpe:2.3:a:emclient:em_client:2.5.6501.0
-
cpe:2.3:a:emclient:em_client:2.5.6507.0
-
cpe:2.3:a:emclient:em_client:2.6.7018.0
-
cpe:2.3:a:emclient:em_client:2.6.7030.0
-
cpe:2.3:a:emclient:em_client:2.6.7033.0
-
cpe:2.3:a:emclient:em_client:2.6.7047.0
-
cpe:2.3:a:emclient:em_client:2.6.7067.0
-
cpe:2.3:a:emclient:em_client:2.6.7096.0
-
cpe:2.3:a:emclient:em_client:2.6.7149.0
-
cpe:2.3:a:emclient:em_client:2.6.7150.0
-
cpe:2.3:a:emclient:em_client:2.6.7222.0
-
cpe:2.3:a:emclient:em_client:2.6.7225.0
-
cpe:2.3:a:emclient:em_client:2.6.7254.0
-
cpe:2.3:a:emclient:em_client:2.6.7323.0
-
cpe:2.3:a:emclient:em_client:2.6.7340.0
-
cpe:2.3:a:emclient:em_client:2.6.7362.0
-
cpe:2.3:a:emclient:em_client:2.6.7366.0
-
cpe:2.3:a:emclient:em_client:2.6.7402.0
-
cpe:2.3:a:emclient:em_client:2.6.7436.0
-
cpe:2.3:a:emclient:em_client:2.6.7445.0
-
cpe:2.3:a:emclient:em_client:2.6.7473.0
-
cpe:2.3:a:emclient:em_client:2.6.7514.0
-
cpe:2.3:a:emclient:em_client:2.6.7605.0
-
cpe:2.3:a:emclient:em_client:2.6.7737.0
-
cpe:2.3:a:emclient:em_client:2.6.7758.0
-
cpe:2.3:a:emclient:em_client:2.6.7767.0
-
cpe:2.3:a:emclient:em_client:2.6.7829.0
-
cpe:2.3:a:emclient:em_client:2.6.7979.0
-
cpe:2.3:a:emclient:em_client:2.6.8005.0
-
cpe:2.3:a:emclient:em_client:2.7.8063.0
-
cpe:2.3:a:emclient:em_client:2.7.8088.0
-
cpe:2.3:a:emclient:em_client:2.7.8095.0
-
cpe:2.3:a:emclient:em_client:2.7.8102.0
-
cpe:2.3:a:emclient:em_client:2.7.8137.0
-
cpe:2.3:a:emclient:em_client:2.7.8149.0
-
cpe:2.3:a:emclient:em_client:2.7.8202.0
-
cpe:2.3:a:emclient:em_client:2.7.8263.0
-
cpe:2.3:a:emclient:em_client:2.7.8288.0
-
cpe:2.3:a:emclient:em_client:2.7.8313.0
-
cpe:2.3:a:emclient:em_client:2.7.8408.0
-
cpe:2.3:a:emclient:em_client:2.7.8468.0
-
cpe:2.3:a:emclient:em_client:2.7.8714.0
-
cpe:2.3:a:emclient:em_client:2.7.8761.0
-
cpe:2.3:a:emclient:em_client:2.7.8773.0
-
cpe:2.3:a:emclient:em_client:3.0.10012.0
-
cpe:2.3:a:emclient:em_client:3.0.10049.0
-
cpe:2.3:a:emclient:em_client:3.0.10053.0
-
cpe:2.3:a:emclient:em_client:3.0.10057.0
-
cpe:2.3:a:emclient:em_client:3.0.10083.0
-
cpe:2.3:a:emclient:em_client:3.0.10099.0
-
cpe:2.3:a:emclient:em_client:3.0.10144.0
-
cpe:2.3:a:emclient:em_client:3.0.10185.0
-
cpe:2.3:a:emclient:em_client:3.0.10192.0
-
cpe:2.3:a:emclient:em_client:3.0.10206.0
-
cpe:2.3:a:emclient:em_client:3.0.10548.0
-
cpe:2.3:a:emclient:em_client:3.0.9422.0
-
cpe:2.3:a:emclient:em_client:3.0.9465.0
-
cpe:2.3:a:emclient:em_client:3.0.9517.0
-
cpe:2.3:a:emclient:em_client:3.0.9543.0
-
cpe:2.3:a:emclient:em_client:3.0.9580.0
-
cpe:2.3:a:emclient:em_client:3.0.9661.0
-
cpe:2.3:a:emclient:em_client:3.0.9716.0
-
cpe:2.3:a:emclient:em_client:3.0.9743.0
-
cpe:2.3:a:emclient:em_client:3.0.9879.0
-
cpe:2.3:a:emclient:em_client:3.0.9914.0
-
cpe:2.3:a:emclient:em_client:3.0.9968.0
-
cpe:2.3:a:emclient:em_client:3.0.9974.0
-
cpe:2.3:a:emclient:em_client:3.0.9991.0
-
cpe:2.3:a:emclient:em_client:3.5.11281.0
-
cpe:2.3:a:emclient:em_client:3.5.11809.0
-
cpe:2.3:a:emclient:em_client:3.5.12574.0
-
cpe:2.3:a:emclient:em_client:3.5.13654.0
-
cpe:2.3:a:emclient:em_client:4.0.13961.0
-
cpe:2.3:a:emclient:em_client:4.0.14479.0
-
cpe:2.3:a:emclient:em_client:4.0.15010.0
-
cpe:2.3:a:emclient:em_client:4.0.15145.0
-
cpe:2.3:a:emclient:em_client:5.0.17263.0
-
cpe:2.3:a:emclient:em_client:5.0.17595.0
-
cpe:2.3:a:emclient:em_client:5.0.18025.0
-
cpe:2.3:a:emclient:em_client:5.0.18661.0
-
cpe:2.3:a:emclient:em_client:5.0.19406.0
-
cpe:2.3:a:emclient:em_client:5.0.20009.0
-
cpe:2.3:a:emclient:em_client:6.0.19106.0
-
cpe:2.3:a:emclient:em_client:6.0.19404.0
-
cpe:2.3:a:emclient:em_client:6.0.19714.0
-
cpe:2.3:a:emclient:em_client:6.0.19825.0
-
cpe:2.3:a:emclient:em_client:6.0.19831.0
-
cpe:2.3:a:emclient:em_client:6.0.19849.0
-
cpe:2.3:a:emclient:em_client:6.0.19861.0
-
cpe:2.3:a:emclient:em_client:6.0.20154.0
-
cpe:2.3:a:emclient:em_client:6.0.20320.0
-
cpe:2.3:a:emclient:em_client:6.0.20480.0
-
cpe:2.3:a:emclient:em_client:6.0.20522.0
-
cpe:2.3:a:emclient:em_client:6.0.20546.0
-
cpe:2.3:a:emclient:em_client:6.0.20617.0
-
cpe:2.3:a:emclient:em_client:6.0.20631.0
-
cpe:2.3:a:emclient:em_client:6.0.20648.0
-
cpe:2.3:a:emclient:em_client:6.0.20899.0
-
cpe:2.3:a:emclient:em_client:6.0.20968.0
-
cpe:2.3:a:emclient:em_client:6.0.21034.0
-
cpe:2.3:a:emclient:em_client:6.0.21040.0
-
cpe:2.3:a:emclient:em_client:6.0.21372.0
-
cpe:2.3:a:emclient:em_client:6.0.22283.0
-
cpe:2.3:a:emclient:em_client:6.0.22298.0
-
cpe:2.3:a:emclient:em_client:6.0.22313.0
-
cpe:2.3:a:emclient:em_client:6.0.22328.0
-
cpe:2.3:a:emclient:em_client:6.0.22344.0
-
cpe:2.3:a:emclient:em_client:6.0.23181.0
-
cpe:2.3:a:emclient:em_client:6.0.23421.0
-
cpe:2.3:a:emclient:em_client:6.0.24144.0
-
cpe:2.3:a:emclient:em_client:6.0.24230.0
-
cpe:2.3:a:emclient:em_client:6.0.24316.0
-
cpe:2.3:a:emclient:em_client:6.0.24928.0
-
cpe:2.3:a:emclient:em_client:6.0.24985.0
-
cpe:2.3:a:emclient:em_client:7.0.26687.0
-
cpe:2.3:a:emclient:em_client:7.0.27804.0
-
cpe:2.3:a:emclient:em_client:7.0.27943.0
-
cpe:2.3:a:emclient:em_client:7.0.28037.0
-
cpe:2.3:a:emclient:em_client:7.0.28822.0
-
cpe:2.3:a:emclient:em_client:7.0.30242.0
-
cpe:2.3:a:emclient:em_client:7.1.30453.0
-
cpe:2.3:a:emclient:em_client:7.1.30508.0
-
cpe:2.3:a:emclient:em_client:7.1.30794.0
-
cpe:2.3:a:emclient:em_client:7.1.30933.0
-
cpe:2.3:a:emclient:em_client:7.1.31085.0
-
cpe:2.3:a:emclient:em_client:7.1.31849.0
-
cpe:2.3:a:emclient:em_client:7.1.31991.0
-
cpe:2.3:a:emclient:em_client:7.1.32792.0
-
cpe:2.3:a:emclient:em_client:7.1.32845.0
-
cpe:2.3:a:emclient:em_client:7.1.33506.0