CVE-2017-17689 describes a CBC malleability-gadget attack within the S/MIME specification, potentially leading to plaintext exfiltration, commonly known as EFAIL. This vulnerability impacts a wide range of email clients and platforms, including products from Apple, Microsoft, Mozilla, and Google. It carries a CVSS score of 5.9 (Medium), indicating a network-based attack with high confidentiality impact but high attack complexity. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit or ExploitDB, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:9folders:nine:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:apple:mail:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:apple:mail:-:*:*:*:*:iphone_os:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:bloop:airmail:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:emclient:emclient:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.