CVE-2023-0547
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2023-0547 is a cybersecurity vulnerability affecting Thunderbird email clients from versions 68 to 102.9.1. This issue allows the acceptance of revoked certificates during the sending of S/Mime encrypted emails. The On-line Certificate Status Protocol (OCSP) revocation check was not implemented, leaving the system unable to verify the status of recipient certificates. Consequently, this vulnerability poses a risk for man-in-the-middle attacks and potential data breaches. Users running Thunderbird versions below 102.10 are advised to update their software to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Mozilla Thunderbird
Affected Vendors
- Mozilla