Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
eM Client before 7.2.33412.0 automatically imported S/MIME certificates and thereby silently replaced existing ones. This allowed a man-in-the-middle attacker to obtain an email-validated S/MIME certificate from a trusted CA and replace the public key of the entity to be impersonated. This enabled the attacker to decipher further communication. The entire attack could be accomplished by sending a single email.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
eM Client 信任管理问题漏洞
Vulnerability Description
eM Client 1.11之前版本中存在安全漏洞,该漏洞源于程序会自动化导入S/MIME证书并且默认替换之前存在的证书。攻击者可通过实施中间人攻击并发送邮件利用该漏洞从CA获取到有效的邮件S/MIME证书并替换公钥,进而猜测将来的通信过程。
CVSS Information
N/A
Vulnerability Type
N/A