ZeroHour

CVE-2020-29547

CVSS 3.1
5.9 medium
EPSS
<1%p53
Published
()
Modified
Description

An issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS, or SMTP STARTTLS commands, injecting cleartext commands into an encrypted user session. This can lead to credential disclosure.

Vendors
citadel
Products
webcit
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.