Impact
The Suricata SMTP MIME parser fails to fully reset state for message/rfc822 encapsulation, allowing outer MIME part encoding or filename attributes to leak into the inner message. This weakness, classified as CWE‑665, permits an attacker to craft an email that bypasses detection rules based on file.data, file.name, or extracted URLs when SMTP MIME decoding is active. An attacker could thus deliver malicious attachments or malicious URLs that slip through monitoring security controls, degrading the integrity and confidentiality of the monitored traffic.
Affected Systems
The issue affects Suricata 8.0.0 through 8.0.5 (inclusive) released by the Open Information Security Foundation. Versions 8.0.6 and newer contain the fix. Vendors relying on the open source Suricata engine and using SMTP MIME decoding must verify their deployed versions against this range.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve sending specially constructed SMTP traffic that leverages message/rfc822 encapsulation via compromised or rogue mail servers. An adversary could use this to subvert detection of file attachments or URLs, potentially aiding phishing or malware distribution campaigns.
OpenCVE Enrichment