QID 50135

Date Published: 2024-01-15

QID 50135: Exim Mail Server Simple Mail Transfer Protocol (SMTP) Smuggling Vulnerability

Exim is a mail transfer agent (MTA) used on Unix-like operating systems. Exim is free software and it aims to be a general and flexible mailer with extensive facilities for checking incoming e-mail.
CVE-2023-51766: Exim allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages that appear to originate from the Exim server, allowing bypass of an SPF protection mechanism.

Affected Versions:
Exim versions up to 4.97

QID Detection Logic (Unauthenticated):
The QID checks for the SMTP banner to check for vulnerable versions of exim.

On successful exploitation, Remote attackers can use a published exploitation technique to inject e-mail messages that appear to originate from the Exim server.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Customer are advised to update to Latest version of Exim.

    Vendor References

    CVEs related to QID 50135

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-51766 URL Logo nvd.nist.gov/vuln/detail/CVE-2023-51766