9.8
CVSSv3

CVE-2019-20790

Published: 27/04/2020 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 607
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

OpenDMARC up to and including 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

trusteddomain opendmarc

trusteddomain opendmarc 1.4.0

pypolicyd-spf_project pypolicyd-spf 2.0.2

fedoraproject fedora 33

fedoraproject fedora 34

Vendor Advisories

Debian Bug report logs - #977766 opendmarc: CVE-2019-20790 Package: src:opendmarc; Maintainer for src:opendmarc is Scott Kitterman <scott@kittermancom>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 20 Dec 2020 13:18:02 UTC Severity: important Tags: security, upstream Found in versions opendmarc/ ...
OpenDMARC through 132 and 14x, when used with pypolicyd-spf 202, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field ...

Github Repositories

An email spoofing testing tool that aims to bypass SPF/DKIM/DMARC and forge DKIM signatures.🍻

espoofer espoofer is an open-source testing tool to bypass SPF, DKIM, and DMARC authentication in email systems It helps mail server administrators and penetration testers to check whether the target email server and client are vulnerable to email spoofing attacks or can be abused to send spoofing emails Figure 1 A case of our spoofing attacks on Gmail (Fixed, Demo vide

A spam test for public mail service based on espoofer.

espoofer espoofer is an open-source testing tool to bypass SPF, DKIM, and DMARC authentication in email systems It helps mail server administrators and penetration testers to check whether the target email server and client are vulnerable to email spoofing attacks or can be abused to send spoofing emails Figure 1 A case of our spoofing attacks on Gmail (Fixed, Demo vide

Espoofer

espoofer espoofer is an open-source testing tool to bypass SPF, DKIM, and DMARC authentication in email systems It helps mail server administrators and penetration testers to check whether the target email server and client are vulnerable to email spoofing attacks or can be abused to send spoofing emails Figure 1 A case of our spoofing attacks on Gmail (Fixed, Demo vide

espoofer espoofer is an open-source testing tool to bypass SPF, DKIM, and DMARC authentication in email systems It helps mail server administrators and penetration testers to check whether the target email server and client are vulnerable to email spoofing attacks or can be abused to send spoofing emails Figure 1 A case of our spoofing attacks on Gmail (Fixed, Demo vide

espoofer espoofer is an open-source testing tool to bypass SPF, DKIM, and DMARC authentication in email systems It helps mail server administrators and penetration testers to check whether the target email server and client are vulnerable to email spoofing attacks or can be abused to send spoofing emails Figure 1 A case of our spoofing attacks on Gmail (Fixed, Demo vide

espoofer espoofer is an open-source testing tool to bypass SPF, DKIM, and DMARC authentication in email systems It helps mail server administrators and penetration testers to check whether the target email server and client are vulnerable to email spoofing attacks or can be abused to send spoofing emails Figure 1 A case of our spoofing attacks on Gmail (Fixed, Demo vide