Vulnerability Description
An issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS, or SMTP STARTTLS commands, injecting cleartext commands into an encrypted user session. This can lead to credential disclosure.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Citadel | Webcit | <= 926 |
Related Weaknesses (CWE)
References
- http://uncensored.citadel.org/dotgoto?room=Citadel%20SecurityIssue Tracking
- http://uncensored.citadel.org/msg/4576039Vendor Advisory
- http://uncensored.citadel.org/dotgoto?room=Citadel%20SecurityIssue Tracking
- http://uncensored.citadel.org/msg/4576039Vendor Advisory
FAQ
What is CVE-2020-29547?
CVE-2020-29547 is a vulnerability with a CVSS score of 5.9 (MEDIUM). An issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS, or SMTP STARTTLS commands, injecting cleartext commands int...
How severe is CVE-2020-29547?
CVE-2020-29547 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-29547?
Check the references section above for vendor advisories and patch information. Affected products include: Citadel Webcit.