CVE-2020-29547
CVSS 3.1 Score 5.9 of 10 (medium)
Details
Summary
CVE-2020-29547 is a vulnerability affecting Citadel's webcit-926 component. This issue permits meddler-in-the-middle attackers to exploit a pipeline command injection vulnerability after POP3 STLS, IMAP STARTTLS, or SMTP STARTTLS commands. By doing so, attackers can inject cleartext commands into an encrypted user session, potentially resulting in credential disclosure. This vulnerability poses a significant risk to users, as attackers can intercept and manipulate data during the secure transmission of sensitive information. Organizations using Citadel are strongly advised to apply the available patch to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Citadel LLC