CVE-2024-23655 is a denial-of-service vulnerability affecting Tuta (Tutanota) email services, specifically versions 3.118.12 through 3.119.9. An attacker can send a specially crafted email that renders the Tuta application and web client unusable for the recipient, preventing access to all received emails. This vulnerability has a CVSS score of 5.3 (Medium), indicating a low-complexity attack that requires no user interaction and results in a low impact on availability. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.118.12, < 3.119.10CPE matchmatch criteria | cpe:2.3:a:tuta:tutanota:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.