SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2011-1429

Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than…

MEDIUM 5.8EPSS 1.47%

Does this matter?

Lower severity and a low EPSS score (1.47%). Track it; it rarely justifies an emergency change on its own.

Description

Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.

CVSS 2.0
5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
EPSS
1.47% probability · 72th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
mutt/mutt
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.