PT-2022-8973 · Mimecast · Mimecast Email Security

Wesley Kirkland

·

Published

2022-03-15

·

Updated

2022-03-22

·

CVE-2020-36519

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mimecast Email Security versions prior to 2020-01-10
Description The issue allows any admin to spoof any domain and pass DMARC alignment via SPF. This occurs through misuse of the address rewrite feature, but the domain being spoofed must be a customer in the Mimecast grid from which the spoofing occurs.
Recommendations For versions prior to 2020-01-10, update to a version released after 2020-01-10 to resolve the issue. As a temporary workaround, consider restricting the use of the address rewrite feature to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-36519

Affected Products

Mimecast Email Security