Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-17689

22
FAUCET Score

CVE-2017-17689 describes a CBC malleability-gadget attack within the S/MIME specification, potentially leading to plaintext exfiltration, commonly known as EFAIL. This vulnerability impacts a wide range of email clients and platforms, including products from Apple, Microsoft, Mozilla, and Google. It carries a CVSS score of 5.9 (Medium), indicating a network-based attack with high confidentiality impact but high attack complexity. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit or ExploitDB, the vulnerability has garnered some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:9folders:nine:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:apple:mail:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:apple:mail:-:*:*:*:*:iphone_os:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:bloop:airmail:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:emclient:emclient:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

5.9MEDIUM

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
4.17%
Probability of exploitation in next 30 days
EPSS Percentile
89.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0417 is in the 87th percentile among its peer group of 19,954 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (2)

redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kdepim
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kdepim

Vendor Advisories (1)

redhatCVE-2017-17689Moderate

S/MIME: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails

May 14, 2018

References

efail.de
ExploitMitigationThird Party Advisory
news.ycombinator.com / item
Issue TrackingThird Party Advisory
pastebin.com / gNCc8aYm
Third Party Advisory
twitter.com / matthew_d_green/status/996371541591019520
Third Party Advisory
synology.com / support/security/Synology_SA_18_22
Third Party Advisory
securityfocus.com / bid/104165
Third Party AdvisoryVDB Entry