Skip to main content

Insufficient Verification of Data Authenticity

CVE-2024-27305

Severity Medium
Score 5.3/10

Summary

The package aiosmtpd is a reimplementation of the Python stdlib "smtpd.py" based on asyncio. aiosmtpd is vulnerable to inbound SMTP smuggling. SMTP smuggling is a novel vulnerability based on not so novel interpretation differences of the SMTP protocol. By exploiting SMTP smuggling, an attacker may send smuggle/spoof e-mails with fake sender addresses, allowing advanced phishing attacks. This issue also exists in other SMTP software like Postfix. With the right SMTP server constellation, an attacker can send spoofed e-mails to inbound/receiving aiosmtpd instances. Users are advised to upgrade. There are no known workarounds for this vulnerability. This issue affects aiosmtpd versions prior to 1.4.5.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • NONE

CWE-345 - Insufficient Verification of Data Authenticity

The software does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

References

Advisory Timeline

  • Published