CVE-2021-37845

CVSS 3.1 Score 3.7 of 10 (low)

Details

Published May 29, 2023
Updated: Jan 14, 2025

Summary

CVE-2021-37845 is a vulnerability affecting Citadel's webcit-932 component. An attacker can exploit this issue by performing a meddler-in-the-middle attack, fixing their own session during the cleartext phase before a STARTTLS command. This violation of RFC2595's rule that "The STARTTLS command is only valid in non-authenticated state" potentially allows an attacker to store a victim's e-mail messages into their own IMAP mailbox, depending on the victim's client behavior.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share