First published: Tue Aug 17 2021(Updated: )
An issue was discovered in SmarterTools SmarterMail through 100.0.7537. Meddler-in-the-middle attackers can pipeline commands after a POP3 STLS command, injecting plaintext commands into an encrypted user session.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SmarterTools SmarterMail | <=100.0.7537 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-29548 is high with a CVSS score of 8.1.
Meddler-in-the-middle attackers can pipeline commands after a POP3 STLS command, injecting plaintext commands into an encrypted user session.
To fix CVE-2020-29548, ensure you are using SmarterTools SmarterMail version 100.0.7537 or higher.
More information about CVE-2020-29548 can be found at the following references: [1] https://nostarttls.secvuln.info/ [2] https://www.smartertools.com/smartermail/release-notes/current
The CWE ID for CVE-2020-29548 is CWE-77.