5.3
CVSSv3

CVE-2020-12272

Published: 27/04/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 447
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

OpenDMARC up to and including 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsing and interpretation of SPF/DKIM authentication results, as demonstrated by the example.net(.example.com substring.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

trusteddomain opendmarc 1.4.0

trusteddomain opendmarc

fedoraproject fedora 33

fedoraproject fedora 34

Vendor Advisories

Debian Bug report logs - #977767 opendmarc: CVE-2020-12272 Package: src:opendmarc; Maintainer for src:opendmarc is Scott Kitterman <scott@kittermancom>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 20 Dec 2020 13:18:05 UTC Severity: important Tags: security, upstream Found in versions opendmarc/ ...
OpenDMARC through 132 and 14x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message This is caused by incorrect parsing and interpretation of SPF/DKIM authentication results, as demonstrated by the examplenet(examplecom substring ...

Github Repositories

An email spoofing testing tool that aims to bypass SPF/DKIM/DMARC and forge DKIM signatures.🍻

espoofer espoofer is an open-source testing tool to bypass SPF, DKIM, and DMARC authentication in email systems It helps mail server administrators and penetration testers to check whether the target email server and client are vulnerable to email spoofing attacks or can be abused to send spoofing emails Figure 1 A case of our spoofing attacks on Gmail (Fixed, Demo vide

A spam test for public mail service based on espoofer.

espoofer espoofer is an open-source testing tool to bypass SPF, DKIM, and DMARC authentication in email systems It helps mail server administrators and penetration testers to check whether the target email server and client are vulnerable to email spoofing attacks or can be abused to send spoofing emails Figure 1 A case of our spoofing attacks on Gmail (Fixed, Demo vide

Espoofer

espoofer espoofer is an open-source testing tool to bypass SPF, DKIM, and DMARC authentication in email systems It helps mail server administrators and penetration testers to check whether the target email server and client are vulnerable to email spoofing attacks or can be abused to send spoofing emails Figure 1 A case of our spoofing attacks on Gmail (Fixed, Demo vide

espoofer espoofer is an open-source testing tool to bypass SPF, DKIM, and DMARC authentication in email systems It helps mail server administrators and penetration testers to check whether the target email server and client are vulnerable to email spoofing attacks or can be abused to send spoofing emails Figure 1 A case of our spoofing attacks on Gmail (Fixed, Demo vide

espoofer espoofer is an open-source testing tool to bypass SPF, DKIM, and DMARC authentication in email systems It helps mail server administrators and penetration testers to check whether the target email server and client are vulnerable to email spoofing attacks or can be abused to send spoofing emails Figure 1 A case of our spoofing attacks on Gmail (Fixed, Demo vide

espoofer espoofer is an open-source testing tool to bypass SPF, DKIM, and DMARC authentication in email systems It helps mail server administrators and penetration testers to check whether the target email server and client are vulnerable to email spoofing attacks or can be abused to send spoofing emails Figure 1 A case of our spoofing attacks on Gmail (Fixed, Demo vide