CVE-2004-2088

3 documents3 sources
Severity
5.0MEDIUM
EPSS
2.4%
top 15.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 12
Latest updateApr 29

Description

Sophos Anti-Virus 3.78 allows remote attackers to bypass virus scanning by using a qmail generated Delivery Status Notification (DSN) where the original email is not included in the bounce message.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDsophos/sophos_anti-virus3.4.6, 3.78+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pc4g-qx8h-rcf5: Sophos Anti-Virus 32022-04-29
CVEList
CVE-2004-2088: Sophos Anti-Virus 32005-05-19
CVE-2004-2088 (MEDIUM CVSS 5) | Sophos Anti-Virus 3.78 allows remot | cvebase.io