CVE-2004-2703: Medium severity Clearswift MAILsweeper Business Suite I vulnerability
Clearswift MIMEsweeper 5.0.5, when it has been upgraded from MAILsweeper for SMTP version 4.3 or MAILsweeper Business Suite I or II, allows remote attackers to bypass scanning by including encrypted data in a mail message, which causes the message to be marked as "Clean" instead of "Encrypted".
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2703?
CVE-2004-2703 is classified as a medium severity vulnerability due to its potential to bypass scanning for encrypted data.
How do I fix CVE-2004-2703?
To mitigate CVE-2004-2703, it is recommended to update or patch the affected Clearswift MIMEsweeper software to the latest version.
Which versions of Clearswift are affected by CVE-2004-2703?
CVE-2004-2703 affects Clearswift MIMEsweeper 5.0.5 and previous versions of MAILsweeper for SMTP 4.3 and the Business Suite I or II.
What can attackers achieve with CVE-2004-2703?
Attackers can bypass email scanning by sending encrypted emails that are incorrectly marked as clean, potentially leading to undiscovered threats.
Is there a workaround for CVE-2004-2703?
A temporary workaround for CVE-2004-2703 involves configuring mail servers to handle encrypted data differently, although updating the software is the preferred solution.