Homoglyph Spoofing Vulnerability in Postfix by ISPs and Enterprises
CVE-2020-12063

5.3MEDIUM

Key Information:

Vendor

Postfix

Status
Vendor
CVE Published:
24 April 2020

What is CVE-2020-12063?

A flaw in the Postfix email server allows an attacker to exploit homoglyph characters to send emails that appear to come from a legitimate source. Specifically, if the sender's address matches a character that looks similar to the actual configured sender in the /etc/postfix/sender_login file, an attacker can bypass standard email blocking mechanisms. This oversight means that outgoing emails using these misleading addresses could successfully be sent, potentially leading to malicious activities without adequate protections in place.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.