CVE-2024-34083
aiosmtpd STARTTLS unencrypted commands injection
5.4
MEDIUM
CVSS 3.1
EPSS 0.07%
Description
aiosmptd is a reimplementation of the Python stdlib smtpd.py based on asyncio. Prior to version 1.4.6, servers based on aiosmtpd accept extra unencrypted commands after STARTTLS, treating them as if they came from inside the encrypted connection. This could be exploited by a man-in-the-middle attack. Version 1.4.6 contains a patch for the issue.
How to fix CVE-2024-34083
To remediate CVE-2024-34083, upgrade the affected package to a fixed version below.
- —upgrade to 1.2.2-1+deb11u1 or later
- —upgrade to 1.4.6 or later
Is CVE-2024-34083 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 1.2.2-1+deb11u1
- from 0, < 1.4.6
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.4 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |