CVE-2021-38373 describes a vulnerability in KDE KMail versions up to 19.12.3 (aka 5.13.3) where the SMTP STARTTLS option is not enforced, leading to cleartext transmission of emails unless server authentication is explicitly enabled. This medium-severity vulnerability (CVSS 5.3) has a high confidentiality impact, allowing an attacker to intercept sensitive information due to the lack of encryption. There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
19.12.3CPE matchmatch criteria | cpe:2.3:a:kde:kmail:19.12.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.