Impact
A function in Trusted Domain Project OpenDMARC, namely opendmarc_policy_query_dmarc within the Multi‑Record Set Handler, is vulnerable to manipulation that allows an attacker to bypass authentication checks. By forging requests to this function, an adversary can spoof DMARC authentication, making legitimate email traffic appear authentic. This permits the delivery of forged or malicious messages to legitimate recipients without triggering standard DMARC defenses.
Affected Systems
The vulnerability impacts all installations of Trusted Domain Project OpenDMARC version 1.4.2 and earlier. The affected component is the Multi‑Record Set Handler in the OpenDMARC package, which is deployed in mail servers and email gateway solutions that rely on DMARC validation.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity impact. The exploit is remote and can be performed by an unauthenticated attacker with network access to the OpenDMARC service. The EPSS score is not available, and the vulnerability is not yet listed in the CISA KEV catalog. Attackers can leverage publicly available exploit code or craft custom requests to trigger the authentication bypass.
OpenCVE Enrichment