SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2002-1121

SMTP content filter engines, including (1) GFI MailSecurity for Exchange/SMTP before 7.2, (2) InterScan VirusWall before 3.52 build 1494, (3) the default configuration of MIMEDefang before 2.21, and possibly other products, do not detect fragmented…

HIGH 7.5EPSS 6.67%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (6.67%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

SMTP content filter engines, including (1) GFI MailSecurity for Exchange/SMTP before 7.2, (2) InterScan VirusWall before 3.52 build 1494, (3) the default configuration of MIMEDefang before 2.21, and possibly other products, do not detect fragmented emails as defined in RFC2046 ("Message Fragmentation and Reassembly") and supported in such products as Outlook Express, which allows remote attackers to bypass content filtering, including virus checking, via fragmented emails of the message/partial content type.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
6.67% probability · 94th percentile
CISA KEV
Not listed
Affected
gfi/mailsecurity · network associates/webshield smtp · roaring penguin/canit · roaring penguin/mimedefang · trend micro/interscan viruswall
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.