6.8

CVE-2011-1430

The STARTTLS implementation in the server in Ipswitch IMail 11.03 and earlier does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IpswitchImail Version <= 11.03
IpswitchImail Version5.0
IpswitchImail Version5.0.5
IpswitchImail Version5.0.6
IpswitchImail Version5.0.7
IpswitchImail Version5.0.8
IpswitchImail Version6.00
IpswitchImail Version6.0
IpswitchImail Version6.0.1
IpswitchImail Version6.0.2
IpswitchImail Version6.0.3
IpswitchImail Version6.0.4
IpswitchImail Version6.0.5
IpswitchImail Version6.0.6
IpswitchImail Version6.1
IpswitchImail Version6.2
IpswitchImail Version6.3
IpswitchImail Version6.4
IpswitchImail Version6.06
IpswitchImail Version7.0.1
IpswitchImail Version7.0.2
IpswitchImail Version7.0.3
IpswitchImail Version7.0.4
IpswitchImail Version7.0.5
IpswitchImail Version7.0.6
IpswitchImail Version7.0.7
IpswitchImail Version7.1
IpswitchImail Version7.12
IpswitchImail Version8.0.3
IpswitchImail Version8.0.5
IpswitchImail Version8.1
IpswitchImail Version8.01
IpswitchImail Version8.11
IpswitchImail Version8.12
IpswitchImail Version8.13
IpswitchImail Version8.22
IpswitchImail Version10
IpswitchImail Version10.01
IpswitchImail Version10.02
IpswitchImail Version11
IpswitchImail Version11.01
IpswitchImail Version11.02
IpswitchImail Version2006
IpswitchImail Version2006.1
IpswitchImail Version2006.2
IpswitchImail Versionserver_8.2_hotfix_2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.42% 0.588
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.