Impact
Improper certificate validation in the webmail component allows a remote unauthenticated attacker to cause the server to retain an untrusted signer's certificate and use it for encrypting replies, enabling the attacker to decrypt later messages. The captured key can be used to read any message later sent to the victim's address that uses the same certificate, leading to unauthorized disclosure of confidential email content.
Affected Systems
Progressive Robot Ltd’s hMailServer email server, particularly the webmail feature in versions 6.3.2 through 6.3.5, is affected. Users running these releases with the webmail interface are at risk.
Risk and Exploitability
The vulnerability has a CVSS score of 5.9, indicating moderate severity, and is not currently listed in the CISA KEV catalog. It can be exploited remotely without authentication, and an attacker can gain access to the cryptographic key used to encrypt future messages, so the potential for data breach exists. Because the attack requires sending a crafted email, an attacker with the ability to send email to the target can trigger the flaw.
OpenCVE Enrichment