CVE-2023-0430
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2023-0430 is a cybersecurity vulnerability that affected Thunderbird email clients from version 68 to 102.7.0. The issue involved a failure to check the Online Certificate Status Protocol (OCSP) revocation status when verifying S/Mime signatures. As a result, emails signed with revoked certificates were erroneously displayed as having valid signatures. This flaw could potentially enable man-in-the-middle attacks or email spoofing, posing a significant security risk to users. Thunderbird users are advised to upgrade to version 102.7.1 or later to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Mozilla Thunderbird
Affected Vendors
- Mozilla