CVE-2011-3355 describes an insecure communication vulnerability in Evolution Data Server 3 versions 3.0.3 through 3.2.1. This flaw causes the software to use unencrypted connections when saving sent emails to a remote server's Sent folder, potentially exposing user login credentials. Rated with a CVSS score of 7.3 (HIGH), this vulnerability has a network attack vector and low complexity, allowing an attacker to potentially compromise confidentiality, integrity, and availability. Its EPSS score is very low, indicating a minimal probability of exploitation. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has garnered no community discussion or media coverage, suggesting a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.3, <= 3.2.1CPE matchmatch criteria | cpe:2.3:a:gnome:evolution-data-server3:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.