CVE-2020-15646
published 2020-10-08CVE-2020-15646: If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the…
PriorityP431medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.96%
57.6th percentile
If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunderbird sends username and password over https to a server controlled by the attacker. This vulnerability affects Thunderbird < 68.10.0.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | thunderbird | < thunderbird 1:68.10.0-1 (bookworm) | thunderbird 1:68.10.0-1 (bookworm) |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 68.10.0 | 68.10.0 |
| mozilla | thunderbird | >= 0 < 1:68.10.0-1 | 1:68.10.0-1 |
| mozilla | thunderbird | >= 0 < 1:68.10.0-1 | 1:68.10.0-1 |
| mozilla | thunderbird | >= 0 < 1:68.10.0-1 | 1:68.10.0-1 |
| mozilla | thunderbird | >= 0 < 1:68.10.0-1 | 1:68.10.0-1 |
| mozilla | thunderbird | >= unspecified < 68.10.0 | 68.10.0 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Automatic account setup leaks Microsoft Exchange login credentials
vendor_redhat·2020-06-30·CVSS 5.9
CVE-2020-15646 [MEDIUM] CWE-200 Mozilla: Automatic account setup leaks Microsoft Exchange login credentials
Mozilla: Automatic account setup leaks Microsoft Exchange login credentials
If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunderbird sends username and password over https to a server controlled by the attacker. This vulnerability affects Thunderbird < 68.10.0.
Package: thunderbird (Red Hat Enterprise Linux 5) - Out of support scope
Debian
CVE-2020-15646: thunderbird - If an attacker intercepts Thunderbird's initial attempt to perform automatic acc...
vendor_debian·2020·CVSS 5.9
CVE-2020-15646 [MEDIUM] CVE-2020-15646: thunderbird - If an attacker intercepts Thunderbird's initial attempt to perform automatic acc...
If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunderbird sends username and password over https to a server controlled by the attacker. This vulnerability affects Thunderbird < 68.10.0.
Scope: local
bookworm: resolved (fixed in 1:68.10.0-1)
bullseye: resolved (fixed in 1:68.10.0-1)
forky: resolved (fixed in 1:68.10.0-1)
sid: resolved (fixed in 1:68.10.0-1)
trixie: resolved (fixed in 1:68.10.0-1)
Mozilla
Mozilla Foundation Security Advisory 2020-26: CVE-2020-15646
vendor_mozilla·CVSS 5.9
CVE-2020-15646 [MEDIUM] Mozilla Foundation Security Advisory 2020-26: CVE-2020-15646
Mozilla Foundation Security Advisory 2020-26
CVE: CVE-2020-15646
Product: Thunderbird
Impact: moderate
Fixed in: Thunderbird 68.10
GHSA
GHSA-4w45-xx62-4547: If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and t
ghsa_unreviewed·2022-05-24
CVE-2020-15646 [MEDIUM] CWE-522 GHSA-4w45-xx62-4547: If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and t
If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunderbird sends username and password over https to a server controlled by the attacker. This vulnerability affects Thunderbird < 68.10.0.
OSV
CVE-2020-15646: If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and t
osv·2020-10-08·CVSS 5.9
CVE-2020-15646 [MEDIUM] CVE-2020-15646: If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and t
If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunderbird sends username and password over https to a server controlled by the attacker. This vulnerability affects Thunderbird < 68.10.0.
No detection rules found.
No public exploits indexed.
2020-10-08
Published