Vulnerability Description
Clearswift MIMEsweeper 5.0.5, when it has been upgraded from MAILsweeper for SMTP version 4.3 or MAILsweeper Business Suite I or II, allows remote attackers to bypass scanning by including encrypted data in a mail message, which causes the message to be marked as "Clean" instead of "Encrypted".
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Clearswift | Mailsweeper Business Suite I | All versions |
| Clearswift | Mailsweeper Business Suite Ii | All versions |
| Clearswift | Mailsweeper For Smtp | 4.3 |
| Clearswift | Mimesweeper For Web | 5.0.5 |
Related Weaknesses (CWE)
References
- http://download.mimesweeper.com/www/TechnicalDocumentation/MSWSMTP505UpdateReadM
- http://secunia.com/advisories/13160Vendor Advisory
- http://www.osvdb.org/11602
- http://www.securityfocus.com/bid/11669
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18035
- http://download.mimesweeper.com/www/TechnicalDocumentation/MSWSMTP505UpdateReadM
- http://secunia.com/advisories/13160Vendor Advisory
- http://www.osvdb.org/11602
- http://www.securityfocus.com/bid/11669
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18035
FAQ
What is CVE-2004-2703?
CVE-2004-2703 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Clearswift MIMEsweeper 5.0.5, when it has been upgraded from MAILsweeper for SMTP version 4.3 or MAILsweeper Business Suite I or II, allows remote attackers to bypass scanning by including encrypted d...
How severe is CVE-2004-2703?
CVE-2004-2703 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-2703?
Check the references section above for vendor advisories and patch information. Affected products include: Clearswift Mailsweeper Business Suite I, Clearswift Mailsweeper Business Suite Ii, Clearswift Mailsweeper For Smtp, Clearswift Mimesweeper For Web.