SMTP Smuggling: New Flaw Lets Attackers Bypass Security and Spoof Emails
ID: f49c0512-d833-59aa-b898-64d9a667ef98
STIX ID: report--f49c0512-d833-59aa-b898-64d9a667ef98
Feed Name: The Hacker News
A new technique named SMTP smuggling abuses inconsistencies in how SMTP servers handle end-of-data sequences to inject additional SMTP commands and submit forged or multiple messages, enabling widespread email spoofing that can bypass DKIM, DMARC, and SPF protections; major vendors and MTAs (Microsoft, GMX, Cisco, Postfix, Sendmail) are affected to varying degrees, CERT/CC issued an advisory, some vendors have patched while certain default configurations (notably Cisco Secure Email) remain exploitable, and mitigations include vendor patches and configuration changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
