Lucene search

K
cve[email protected]CVE-2003-1485
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2003-1485

2022-10-0316:15:41
CWE-20
web.nvd.nist.gov
15
clearswift
mailsweeper
filtering
bypass
vulnerability
remote attackers
cve-2003-1485
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

7.1 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

57.1%

Clearswift MAILsweeper 4.0 through 4.3.7 allows remote attackers to bypass filtering via a file attachment that contains “multiple extensions combined with large blocks of white space.”

Affected configurations

NVD
Node
clearswiftmailsweeperMatch4.0
OR
clearswiftmailsweeperMatch4.1
OR
clearswiftmailsweeperMatch4.2
OR
clearswiftmailsweeperMatch4.3
OR
clearswiftmailsweeperMatch4.3.3
OR
clearswiftmailsweeperMatch4.3.4
OR
clearswiftmailsweeperMatch4.3.5
OR
clearswiftmailsweeperMatch4.3.6
OR
clearswiftmailsweeperMatch4.3.6_sp1
OR
clearswiftmailsweeperMatch4.3.7

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

7.1 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

57.1%

Related for CVE-2003-1485