First published: Tue Apr 20 2021(Updated: )
IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to non-existent local-domain recipients to the SMTP server, caused by using a non-default configuration. An attacker could exploit this vulnerability to consume unnecessary network bandwidth and disk space, and allow remote attackers to send spam email. IBM X-Force ID: 198056.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM OS/400 | =7.1 | |
IBM OS/400 | =7.2 | |
IBM OS/400 | =7.3 | |
IBM OS/400 | =7.4 | |
IBM OS/400 | <=7.4 | |
IBM OS/400 | <=7.3 | |
IBM OS/400 | <=7.2 | |
IBM OS/400 | <=7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20501 has a medium severity rating due to the potential for network resource consumption.
To mitigate CVE-2021-20501, review and adjust the SMTP server configuration to prevent emails to non-existent local-domain recipients.
CVE-2021-20501 affects IBM i versions 7.1, 7.2, 7.3, and 7.4.
CVE-2021-20501 can lead to excessive consumption of network bandwidth and disk space.
Yes, CVE-2021-20501 can be exploited by remote attackers through the SMTP server.