CVE-2002-2423 affects Sendmail versions 8.12.0 through 8.12.6, allowing remote attackers to obscure their IP address in logs. This vulnerability arises because Sendmail truncates log messages exceeding 100 characters, enabling an attacker to send a long IDENT response to prevent their IP from being recorded. With a CVSS score of 6.4, it is a medium-severity vulnerability that can be exploited remotely with low attack complexity, potentially leading to information disclosure (IP address obfuscation). While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness despite its age.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.12.0CPE matchmatch criteria | cpe:2.3:a:sendmail:sendmail:8.12.0:*:*:*:*:*:*:* | ||
8.12.1CPE matchmatch criteria | cpe:2.3:a:sendmail:sendmail:8.12.1:*:*:*:*:*:*:* | ||
8.12.2CPE matchmatch criteria | cpe:2.3:a:sendmail:sendmail:8.12.2:*:*:*:*:*:*:* | ||
8.12.3CPE matchmatch criteria | cpe:2.3:a:sendmail:sendmail:8.12.3:*:*:*:*:*:*:* | ||
8.12.4CPE matchmatch criteria | cpe:2.3:a:sendmail:sendmail:8.12.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.