← Back

CVE-2012-3523

nvd nist
Published: Nov 11, 2012Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

The STARTTLS implementation in nnrpd in INN before 2.5.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.

Affected (17)

Products: Isc: Inn
1 product
Inn
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
Isc
Up to 2.5.2
Version 1.4
Version 1.4sec2
Version 1.4sec
Version 1.4unoff3
Version 1.4unoff4
Version 1.5.1
Version 1.5
Version 1.7.2
Version 1.7
Version 2.0
Version 2.1
Version 2.2.1
Version 2.2.2
Version 2.2.3
Version 2.2
Version 2.4.0

Related CWEs

References (6)

Timeline

No history available yet.