7.4
CVSSv3

CVE-2021-26911

Published: 17/02/2021 Updated: 24/02/2021
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.4 | Impact Score: 5.2 | Exploitability Score: 2.2
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

core/imap/MCIMAPSession.cpp in Canary Mail prior to 3.22 has Missing SSL Certificate Validation for IMAP in STARTTLS mode.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

canarymail canary mail 3.20

canarymail canary mail 3.21

libmailcore mailcore2 0.6.4

Mailing Lists

Hello, Rayd Debbas of CENSUS identified that Canary Mail versions 320 and 321 (and possibly previous versions) do not perform a certificate validation check when configured for IMAP in STARTTLS mode This bug affects Canary Mail builds for Apple MacOS and iOS It is thus possible to carry out a man-in-the-middle attack in such scenarios, and vi ...