
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-34083 affects aiosmtpd, a reimplementation of the Python stdlib smtpd.py based on asyncio. Prior to version 1.4.6, servers based on aiosmtpd were vulnerable to a security issue where they would accept extra unencrypted commands after STARTTLS, treating them as if they came from inside the encrypted connection. The vulnerability was discovered and disclosed on May 18, 2024 (NVD).
The vulnerability is classified as a moderate severity issue with a CVSS v3.1 base score of 5.4. The vulnerability is categorized under CWE-349 (Acceptance of Extraneous Untrusted Data With Trusted Data). The issue specifically relates to how the server handles commands during the STARTTLS transition, where unencrypted commands could be processed as if they were part of the encrypted connection (GitHub Advisory).
This vulnerability could be exploited by a man-in-the-middle (MitM) attacker to potentially intercept or manipulate email communications. The impact primarily affects confidentiality and integrity of the communication, with CVSS metrics indicating low impact on both these aspects (GitHub Advisory).
The vulnerability requires an adjacent network attack vector with low attack complexity and no privileges or user interaction required. The attack can be executed by a MitM attacker who can modify connections between the client and server (GitHub Advisory, NO STARTTLS).
The vulnerability has been patched in version 1.4.6 of aiosmtpd. The fix includes clearing unencrypted commands from the buffer during the STARTTLS transition (GitHub Commit). Users are advised to upgrade to version 1.4.6 or later to address this security issue.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."