SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-23943

In affected versions the SMTP, IMAP and Sieve host fields allowed to scan for internal services and servers reachable from within the local network of the Nextcloud Server.

MEDIUM 4.3EPSS 0.92%

Does this matter?

Lower severity and a low EPSS score (0.92%). Track it; it rarely justifies an emergency change on its own.

Description

Nextcloud mail is an email app for the nextcloud home server platform. In affected versions the SMTP, IMAP and Sieve host fields allowed to scan for internal services and servers reachable from within the local network of the Nextcloud Server. It is recommended that the Nextcloud Maill app is upgraded to 1.15.0 or 2.2.2. The only known workaround for this issue is to completely disable the nextcloud mail app.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
0.92% probability · 58th percentile
CISA KEV
Not listed
Weakness
CWE-918
Affected
nextcloud/mail
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.