5.9 CVE-2017-17689

Enriched by CISA Exploit
 

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
https://nvd.nist.gov/vuln/detail/CVE-2017-17689

Categories

CWE-NVD-noinfo

References

af854a3a-2127-422b-91ae-364da2661108 Exploit

cve@mitre.org Exploit


 

AFFECTED (from MITRE)


Vendor Product Versions
n/a n/a
  • n/a [affected]
© 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

CPE

cpe start end
Configuration 1
cpe:2.3:a:9folders:nine:-:*:*:*:*:*:*:*
cpe:2.3:a:apple:mail:-:*:*:*:*:*:*:*
cpe:2.3:a:apple:mail:-:*:*:*:*:iphone_os:*:*
cpe:2.3:a:bloop:airmail:-:*:*:*:*:*:*:*
cpe:2.3:a:emclient:emclient:-:*:*:*:*:*:*:*
cpe:2.3:a:flipdogsolutions:maildroid:-:*:*:*:*:*:*:*
cpe:2.3:a:freron:mailmate:-:*:*:*:*:*:*:*
cpe:2.3:a:gnome:evolution:-:*:*:*:*:*:*:*
cpe:2.3:a:google:gmail:-:*:*:*:*:*:*:*
cpe:2.3:a:horde:horde_imp:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:notes:-:*:*:*:*:*:*:*
cpe:2.3:a:kde:kmail:-:*:*:*:*:*:*:*
cpe:2.3:a:kde:trojita:-:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:outlook:2007:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:outlook:2010:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:outlook:2013:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:outlook:2016:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:-:*:*:*:*:*:*:*
cpe:2.3:a:postbox-inc:postbox:-:*:*:*:*:*:*:*
cpe:2.3:a:r2mail2:r2mail2:-:*:*:*:*:*:*:*
cpe:2.3:a:ritlabs:the_bat:-:*:*:*:*:*:*:*


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
No known exploits

Other Nist (github, ...)

Url
https://efail.de
https://efail.de


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry