CVE-2011-1430

UnknownEPSS 3.21%

Last modified

CVE-2011-1430 is a vulnerability of currently unknown severity. The STARTTLS implementation in the server in Ipswitch IMail 11.03 and earlier does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.. EPSS estimates a 3.21% chance of exploitation in the next 30 days.

Description

The STARTTLS implementation in the server in Ipswitch IMail 11.03 and earlier does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.

Metrics

EPSS Probability
3.21%

86.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IpswitchImailAll versions
IpswitchImail<= 11.03
IpswitchImail5.0
IpswitchImail5.0.5
IpswitchImail5.0.6
IpswitchImail5.0.7
IpswitchImail5.0.8
IpswitchImail6.00
IpswitchImail6.0
IpswitchImail6.0.1
IpswitchImail6.0.2
IpswitchImail6.0.3
IpswitchImail6.0.4
IpswitchImail6.0.5
IpswitchImail6.0.6
IpswitchImail6.1
IpswitchImail6.2
IpswitchImail6.3
IpswitchImail6.4
IpswitchImail6.06
IpswitchImail7.0.1
IpswitchImail7.0.2
IpswitchImail7.0.3
IpswitchImail7.0.4
IpswitchImail7.0.5
IpswitchImail7.0.6
IpswitchImail7.0.7
IpswitchImail7.1
IpswitchImail7.12
IpswitchImail8.0.3
IpswitchImail8.0.5
IpswitchImail8.1
IpswitchImail8.01
IpswitchImail8.11
IpswitchImail8.12
IpswitchImail8.13
IpswitchImail8.22
IpswitchImail10
IpswitchImail10.01
IpswitchImail10.02
IpswitchImail11
IpswitchImail11.01
IpswitchImail11.02
IpswitchImail2006
IpswitchImail2006.1
IpswitchImail2006.2
IpswitchImailserver_8.2_hotfix_2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2011-1430?
The STARTTLS implementation in the server in Ipswitch IMail 11.03 and earlier does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.
How severe is CVE-2011-1430?
Severity scoring for CVE-2011-1430 is pending analysis. The EPSS model estimates a 3.21% probability of exploitation in the next 30 days.
How do I fix CVE-2011-1430?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2011-1430?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST