CVE-2020-29548: Command Injection
Published Aug 17, 2021
·Updated
An issue was discovered in SmarterTools SmarterMail through 100.0.7537. Meddler-in-the-middle attackers can pipeline commands after a POP3 STLS command, injecting plaintext commands into an encrypted user session.
Affected Software
1 affected component
SmarterTools SmarterMail<=100.0.7537
Event History
Aug 17, 2021
CVE Published
via MITRE·05:16 PM
Data Sourced
via MITRE·05:16 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-29548?
The severity of CVE-2020-29548 is high with a CVSS score of 8.1.
2
How can a meddler-in-the-middle attack exploit CVE-2020-29548?
Meddler-in-the-middle attackers can pipeline commands after a POP3 STLS command, injecting plaintext commands into an encrypted user session.
3
How can I fix CVE-2020-29548?
To fix CVE-2020-29548, ensure you are using SmarterTools SmarterMail version 100.0.7537 or higher.
4
Where can I find more information about CVE-2020-29548?
More information about CVE-2020-29548 can be found at the following references: [1] https://nostarttls.secvuln.info/ [2] https://www.smartertools.com/smartermail/release-notes/current
5
What is the CWE ID for CVE-2020-29548?
The CWE ID for CVE-2020-29548 is CWE-77.