CVE-2007-1558 describes a design-level vulnerability in the APOP protocol that allows remote attackers to guess the first three characters of a password through man-in-the-middle (MITM) attacks leveraging crafted message IDs and MD5 collisions. This issue affects numerous products utilizing APOP, including specific versions of Thunderbird, Evolution, mutt, fetchmail, SeaMonkey, Balsa, and Mailfilter. The vulnerability has a CVSS score of 2.6, indicating low severity, with an attack vector requiring network access and high attack complexity, but only resulting in partial confidentiality impact (password guessing). There is no impact on integrity or availability. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low attention from security researchers and the public.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:apop_protocol:apop_protocol:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.