Mimecast Email Security before 2020-01-10 allows any admin to spoof any domain, and pass DMARC alignment via SPF. This occurs through misuse of the address rewrite feature. (The domain being spoofed must be a customer in the Mimecast grid from which the spoofing occurs.)
References
Link | Resource |
---|---|
https://wesleyk.me/2020/01/10/my-first-vulnerability-mimecast-sender-address-verification/ | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-03-15 17:15
Updated : 2022-03-22 09:11
NVD link : CVE-2020-36519
Mitre link : CVE-2020-36519
JSON object : View
CWE
Products Affected
mimecast
- email_security