SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2003-0468

Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct "bounce scans" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a "!" string, which causes…

MEDIUM 5.0EPSS 2.38%

Does this matter?

Lower severity and a low EPSS score (2.38%). Track it; it rarely justifies an emergency change on its own.

Description

Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct "bounce scans" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a "!" string, which causes Postfix to attempt to use SMTP to communicate with the target on the associated port.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS
2.38% probability · 83th percentile
CISA KEV
Not listed
Affected
wietse venema/postfix · conectiva/linux
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.