cbcvebase.
CVE-2020-12272
published 2020-04-27

CVE-2020-12272: OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail…

PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
2.14%
80.1th percentile
OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsing and interpretation of SPF/DKIM authentication results, as demonstrated by the example.net(.example.com substring.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianopendmarc< opendmarc 1.4.0~beta1+dfsg-4 (bookworm)opendmarc 1.4.0~beta1+dfsg-4 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
trusteddomainopendmarc
trusteddomainopendmarc>= 0 < 1.4.0~beta1+dfsg-41.4.0~beta1+dfsg-4
trusteddomainopendmarc>= 0 < 1.4.0~beta1+dfsg-41.4.0~beta1+dfsg-4
trusteddomainopendmarc>= 0 < 1.4.0~beta1+dfsg-41.4.0~beta1+dfsg-4
trusteddomainopendmarc>= 0 < 1.4.0~beta1+dfsg-41.4.0~beta1+dfsg-4
trusteddomainopendmarc>= 0 < 1.3.2-3ubuntu0.21.3.2-3ubuntu0.2
trusteddomainopendmarc>= 0 < 1.3.2-7ubuntu0.11.3.2-7ubuntu0.1
trusteddomainopendmarc>= 0 < 1.3.1+dfsg-3ubuntu0.1~esm11.3.1+dfsg-3ubuntu0.1~esm1
trusteddomainopendmarc1.0.0 – 1.3.2

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.