Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-15953

LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a meddler-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 78.3%
CVSS Severity
CVSS v3 Score 7.4
CVSS v2 Score 5.8
References
Products affected by CVE-2020-15953


Contact Us

Shodan ® - All rights reserved