Impact
The vulnerability allows an attacker on the network path between an hMailServer instance and a recipient's mail exchanger to suppress or break the STARTTLS negotiation, resulting in messages being sent in cleartext. Progressive Robot hMailServer 6.0.0 through 6.3.5 does not enforce TLS for outbound SMTP delivery to hosts whose DNSSEC‑validated TLSA set contains no DANE‑EE record, causing the server to fall back to opportunistic TLS. This defect violates RFC 7672 section 2.2 and is a classic CWE‑319 problem, exposing message contents to eavesdropping or modification.
Affected Systems
Vendors: Progressive Robot Ltd. Products: hMailServer 6.0.0 through 6.3.5. Versions older than 6.3.6 are affected. No other versions are impacted.
Risk and Exploitability
The CVSS v3.1 score of 7.4 classifies the vulnerability as high severity. Exploitation requires an attacker to position themselves on the network path between the mail server and the recipient's mail exchanger; no privileged access to the server is necessary. The EPSS score is not available and the vulnerability is not listed in CISA KEV, indicating no widespread exploitation observed yet. Nevertheless, the risk remains high for any environment that sends mail to domains whose TLSA sets lack DANE‑EE records.
OpenCVE Enrichment