5.9

CVE-2017-17689

Exploit

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

Data is provided by the National Vulnerability Database (NVD)
9foldersNine Version-
AppleMail Version-
AppleMail Version- SwPlatformiphone_os
BloopAirmail Version-
EmclientEmclient Version-
FreronMailmate Version-
GnomeEvolution Version-
GoogleGmail Version-
HordeHorde Imp Version-
IbmNotes Version-
KdeKmail Version-
KdeTrojita Version-
MicrosoftOutlook Version2007
MicrosoftOutlook Version2010
MicrosoftOutlook Version2013
MicrosoftOutlook Version2016
MozillaThunderbird Version-
Postbox-incPostbox Version-
R2mail2R2mail2 Version-
RitlabsThe Bat Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.87% 0.744
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N