CVE-2020-15646
If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunderbird sends username and password over https to a…
Does this matter?
Lower severity and a low EPSS score (0.96%). Track it; it rarely justifies an emergency change on its own.
Description
If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunderbird sends username and password over https to a server controlled by the attacker. This vulnerability affects Thunderbird < 68.10.0.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.96% probability · 60th percentile
- CISA KEV
- Not listed
- Affected
- mozilla/thunderbird
- Source
- security@mozilla.org
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1606610Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-26/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1606610Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-26/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.