Impact
Exim before version 4.100.1 is vulnerable when the Proxy-Protocol header is supplied by an attacker-controlled proxy. The flaw allows an attacker to read certain uninitialized data from the stack during handling of the Proxy-Protocol, resulting in the disclosure of potentially sensitive information. This is a classic information-disclosure vulnerability (CWE-908) that can compromise confidentiality.
Affected Systems
Users running Exim versions older than 4.100.1 are at risk. The affected product is the Exim mail transfer agent, with all releases prior to the 4.100.1 patch. The CVE applies broadly to any deployment that enables Proxy-Protocol handling without restricting the source of the proxy.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5 and does not have an EPSS value or KEV listing. Attackers can potentially exploit it remotely by injecting a malicious Proxy-Protocol header through a trusted proxy. Since it hinges on configuration, the exploitation likelihood is tied to an attacker’s ability to control the proxy, but the impact remains significant once achieved.
OpenCVE Enrichment