Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24766
HistoryApr 10, 2020 - 1:03 a.m.

Man-in-the-Middle (MitM)

2020-04-1001:03:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.011 Low

EPSS

Percentile

84.3%

cyrus-imapd is vulnerable to man-in-the-middle (MitM). The vulnerability exists as it was discovered that cyrus-imapd did not flush the received commands buffer after switching to TLS encryption for IMAP, LMTP, NNTP, and POP3 sessions. A man-in-the-middle attacker could use this flaw to inject protocol commands into a victim’s TLS session initialization messages. This could lead to those commands being processed by cyrus-imapd, potentially allowing the attacker to steal the victim’s mail or authentication credentials.

References