The STARTTLS implementation in the server in Ipswitch IMail 11.03 and earlier does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.
2011-03-16T22:55:04.747
2025-04-11T00:51:21.963
Deferred
CVSSv2: 6.8 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ipswitch | imail | * | Yes |
Application | ipswitch | imail | ≤ 11.03 | Yes |
Application | ipswitch | imail | 5.0 | Yes |
Application | ipswitch | imail | 5.0.5 | Yes |
Application | ipswitch | imail | 5.0.6 | Yes |
Application | ipswitch | imail | 5.0.7 | Yes |
Application | ipswitch | imail | 5.0.8 | Yes |
Application | ipswitch | imail | 6.00 | Yes |
Application | ipswitch | imail | 6.0 | Yes |
Application | ipswitch | imail | 6.0.1 | Yes |
Application | ipswitch | imail | 6.0.2 | Yes |
Application | ipswitch | imail | 6.0.3 | Yes |
Application | ipswitch | imail | 6.0.4 | Yes |
Application | ipswitch | imail | 6.0.5 | Yes |
Application | ipswitch | imail | 6.0.6 | Yes |
Application | ipswitch | imail | 6.1 | Yes |
Application | ipswitch | imail | 6.2 | Yes |
Application | ipswitch | imail | 6.3 | Yes |
Application | ipswitch | imail | 6.4 | Yes |
Application | ipswitch | imail | 6.06 | Yes |
Application | ipswitch | imail | 7.0.1 | Yes |
Application | ipswitch | imail | 7.0.2 | Yes |
Application | ipswitch | imail | 7.0.3 | Yes |
Application | ipswitch | imail | 7.0.4 | Yes |
Application | ipswitch | imail | 7.0.5 | Yes |
Application | ipswitch | imail | 7.0.6 | Yes |
Application | ipswitch | imail | 7.0.7 | Yes |
Application | ipswitch | imail | 7.1 | Yes |
Application | ipswitch | imail | 7.12 | Yes |
Application | ipswitch | imail | 8.0.3 | Yes |
Application | ipswitch | imail | 8.0.5 | Yes |
Application | ipswitch | imail | 8.1 | Yes |
Application | ipswitch | imail | 8.01 | Yes |
Application | ipswitch | imail | 8.11 | Yes |
Application | ipswitch | imail | 8.12 | Yes |
Application | ipswitch | imail | 8.13 | Yes |
Application | ipswitch | imail | 8.22 | Yes |
Application | ipswitch | imail | 10 | Yes |
Application | ipswitch | imail | 10.01 | Yes |
Application | ipswitch | imail | 10.02 | Yes |
Application | ipswitch | imail | 11 | Yes |
Application | ipswitch | imail | 11.01 | Yes |
Application | ipswitch | imail | 11.02 | Yes |
Application | ipswitch | imail | 2006 | Yes |
Application | ipswitch | imail | 2006.1 | Yes |
Application | ipswitch | imail | 2006.2 | Yes |
Application | ipswitch | imail | server_8.2_hotfix_2 | Yes |