CVE-2024-7209
CVE-2024-7209

6.5MEDIUM

Key Information:

Vendor

Netwin

Vendor
CVE Published:
30 July 2024

Badges

đź“° News Worthy

What is CVE-2024-7209?

A vulnerability exists in the use of shared SPF records in multi-tenant hosting providers, allowing attackers to use network authorization to be abused to spoof the email identify of the sender.

Affected Version(s)

Fastmail Current

NetWin Current

News Articles

Multiple SMTP Servers Vulnerable to Spoofing Attacks, Hackers Bypassing Authentication

A recent discovery has unveiled vulnerabilities in multiple hosted, outbound SMTP servers, allowing authenticated users.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • đź“°

    First article discovered by CybersecurityNews

  • Vulnerability published

.