CVE-2023-0547

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jun 2, 2023
Updated: Jan 10, 2025
CWE ID 295

Summary

CVE-2023-0547 is a cybersecurity vulnerability affecting Thunderbird email clients from versions 68 to 102.9.1. This issue allows the acceptance of revoked certificates during the sending of S/Mime encrypted emails. The On-line Certificate Status Protocol (OCSP) revocation check was not implemented, leaving the system unable to verify the status of recipient certificates. Consequently, this vulnerability poses a risk for man-in-the-middle attacks and potential data breaches. Users running Thunderbird versions below 102.10 are advised to update their software to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Mozilla Thunderbird

Affected Vendors

  • Mozilla