Impact
Exim before version 4.100.1 is vulnerable to SMTP smuggling, where the mail server accepts data that can be crafted after a DATA rejection, causing the received message to differ from the sent message. This flaw allows an attacker to inject unauthorized content into mail flows, potentially leading to spoofed or forged emails. The weakness is classified as CWE-93.
Affected Systems
The vulnerability affects any deployment of the Exim mail transfer agent older than version 4.100.1. The vendor is Exim, and the product is Exim. No specific release numbering beyond that threshold is known from the advisory, so it is advisable to treat all older releases as vulnerable.
Risk and Exploitability
The CVSS score of 4 indicates a moderate impact, whereas the EPSS score is not available, leaving the likelihood of exploitation uncertain. The vulnerability can be triggered remotely over the SMTP interface by sending crafted commands after an intermediate DATA rejection, so no local privilege is required. Since it is not listed in the CISA Known Exploited Vulnerabilities catalog, there are no confirmed public exploits yet, but the potential for message injection warrants mitigation.
OpenCVE Enrichment