PT-2022-8973 · Mimecast · Mimecast Email Security
Wesley Kirkland
·
Published
2022-03-15
·
Updated
2022-03-22
·
CVE-2020-36519
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Mimecast Email Security versions prior to 2020-01-10
Description
The issue allows any admin to spoof any domain and pass DMARC alignment via SPF. This occurs through misuse of the address rewrite feature, but the domain being spoofed must be a customer in the Mimecast grid from which the spoofing occurs.
Recommendations
For versions prior to 2020-01-10, update to a version released after 2020-01-10 to resolve the issue. As a temporary workaround, consider restricting the use of the address rewrite feature to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mimecast Email Security