Impact
The vulnerability lies in the strcasecmp function of OpenDMARC’s policy parser, where exceptional conditions are incorrectly handled. A crafted comparison can cause the library to execute unintended operations, potentially leading to crashes or other anomalous behavior. The attack vector is remote, and a public exploit is available, meaning the weakness can be leveraged without local access.
Affected Systems
Trusted Domain Project OpenDMARC versions up to 1.4.2 are affected. Any installation of this software that has not been upgraded beyond this release remains vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity vulnerability. No EPSS score is available, and the issue is not listed on the CISA KEV catalog. Because the exploit is publicly available and the attack can be performed remotely, operators must treat the risk as significant until a patch is applied.
OpenCVE Enrichment