CVE-2021-20501: High severity ibm iseries as/400 vulnerability
IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to non-existent local-domain recipients to the SMTP server, caused by using a non-default configuration. An attacker could exploit this vulnerability to consume unnecessary network bandwidth and disk space, and allow remote attackers to send spam email. IBM X-Force ID: 198056.
Other sources
IBM i SMTP allows a network attacker to send emails to non-existent local-domain recipients to the SMTP server, caused by using a non-default configuration. An attacker could exploit this vulnerability to consume unnecessary network bandwidth and disk space, and allow remote attackers to send spam email.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20501?
CVE-2021-20501 has a medium severity rating due to the potential for network resource consumption.
How do I fix CVE-2021-20501?
To mitigate CVE-2021-20501, review and adjust the SMTP server configuration to prevent emails to non-existent local-domain recipients.
What versions of IBM i are affected by CVE-2021-20501?
CVE-2021-20501 affects IBM i versions 7.1, 7.2, 7.3, and 7.4.
What impact does CVE-2021-20501 have on network resources?
CVE-2021-20501 can lead to excessive consumption of network bandwidth and disk space.
Can CVE-2021-20501 be exploited remotely?
Yes, CVE-2021-20501 can be exploited by remote attackers through the SMTP server.