CVE-2018-7702
SecurEnvoy SecurMail before 9.2.501 allows remote attackers to spoof transmission of arbitrary e-mail messages, resend e-mail messages to arbitrary recipients, or modify arbitrary message bodies and attachments by leveraging missing authentication and…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.0%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
SecurEnvoy SecurMail before 9.2.501 allows remote attackers to spoof transmission of arbitrary e-mail messages, resend e-mail messages to arbitrary recipients, or modify arbitrary message bodies and attachments by leveraging missing authentication and authorization.
- CVSS 3.0
- 9.1 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 13.96% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- securenvoy/securmail
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2018/Mar/29Mailing List, Third Party Advisory
- https://www.exploit-db.com/exploits/44285/Third Party Advisory, VDB Entry
- https://www.sec-consult.com/en/blog/advisories/multiple-critical-vulnerabilities-in-securenvoy-securmail/index.htmlThird Party Advisory
- http://seclists.org/fulldisclosure/2018/Mar/29Mailing List, Third Party Advisory
- https://www.exploit-db.com/exploits/44285/Third Party Advisory, VDB Entry
- https://www.sec-consult.com/en/blog/advisories/multiple-critical-vulnerabilities-in-securenvoy-securmail/index.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.