Vulnerability Details CVE-2021-38373
In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.0%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 3.5
Products affected by CVE-2021-38373
-
cpe:2.3:a:kde:kmail:19.12.3