← Back

CVE-2014-2014

nvd nist
Published: Apr 18, 2014Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

imapsync before 1.584, when running with the --tls option, attempts a cleartext login when a certificate verification failure occurs, which allows remote attackers to obtain credentials by sniffing the network.

Affected (15)

Imapsync
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Imapsync Project
Up to 1.580
Version 1.500
Version 1.504
Version 1.508
Version 1.516
Version 1.518
Version 1.525
Version 1.53
Version 1.542
Version 1.547
Version 1.554
Version 1.558
Version 1.564
Version 1.567
Version 1.569

Related CWEs

Timeline

No history available yet.