6.8

CVE-2011-1506

The STARTTLS implementation in Kerio Connect 7.1.4 build 2985 and MailServer 6.x does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.  NOTE: some of these details are obtained from third party information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
KerioConnect Version7.1.4
KerioKerio Mailserver Version5.0
KerioKerio Mailserver Version5.1
KerioKerio Mailserver Version5.1.1
KerioKerio Mailserver Version5.6.3
KerioKerio Mailserver Version5.6.4
KerioKerio Mailserver Version5.6.5
KerioKerio Mailserver Version5.7.0
KerioKerio Mailserver Version5.7.1
KerioKerio Mailserver Version5.7.2
KerioKerio Mailserver Version5.7.3
KerioKerio Mailserver Version5.7.4
KerioKerio Mailserver Version5.7.5
KerioKerio Mailserver Version5.7.6
KerioKerio Mailserver Version5.7.7
KerioKerio Mailserver Version5.7.8
KerioKerio Mailserver Version5.7.9
KerioKerio Mailserver Version5.7.10
KerioKerio Mailserver Version6.0
KerioKerio Mailserver Version6.0.0
KerioKerio Mailserver Version6.0.1
KerioKerio Mailserver Version6.0.2
KerioKerio Mailserver Version6.0.3
KerioKerio Mailserver Version6.0.4
KerioKerio Mailserver Version6.0.5
KerioKerio Mailserver Version6.0.6
KerioKerio Mailserver Version6.0.7
KerioKerio Mailserver Version6.0.8
KerioKerio Mailserver Version6.0.9
KerioKerio Mailserver Version6.0.10
KerioKerio Mailserver Version6.1.1
KerioKerio Mailserver Version6.1.2
KerioKerio Mailserver Version6.1.3
KerioKerio Mailserver Version6.1.3_patch_1
KerioKerio Mailserver Version6.1.4
KerioKerio Mailserver Version6.2.0
KerioKerio Mailserver Version6.2.1
KerioKerio Mailserver Version6.2.2
KerioKerio Mailserver Version6.3.0
KerioKerio Mailserver Version6.3.1
KerioKerio Mailserver Version6.3.1_p1
KerioKerio Mailserver Version6.3.1_p2
KerioKerio Mailserver Version6.4.0
KerioKerio Mailserver Version6.4.1
KerioKerio Mailserver Version6.4.2
KerioKerio Mailserver Version6.5.0
KerioKerio Mailserver Version6.5.0 Updatepatch_1
KerioKerio Mailserver Version6.5.1
KerioKerio Mailserver Version6.5.2
KerioKerio Mailserver Version6.6.0
KerioKerio Mailserver Version6.6.0 Updatepatch_1
KerioKerio Mailserver Version6.6.1
KerioKerio Mailserver Version6.6.2
KerioKerio Mailserver Version6.7.0
KerioKerio Mailserver Version6.7.1
KerioKerio Mailserver Version6.7.2
KerioKerio Mailserver Version6.7.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.99% 0.887
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.