CVE Vulnerabilities

CVE-2020-15954

Cleartext Transmission of Sensitive Information

Published: Jul 27, 2020 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

NameVendorStart VersionEnd Version
KmailKde19.12.3 (including)19.12.3 (including)
Kdepim-runtimeUbuntubionic*
Kdepim-runtimeUbuntufocal*
Kdepim-runtimeUbuntugroovy*
Kdepim-runtimeUbuntuhirsute*
Kdepim-runtimeUbuntuimpish*
Kdepim-runtimeUbuntukinetic*
Kdepim-runtimeUbuntulunar*
Kdepim-runtimeUbuntumantic*
Kdepim-runtimeUbuntuoracular*
Kdepim-runtimeUbuntuplucky*
Kdepim-runtimeUbuntutrusty*
Kdepim-runtimeUbuntuxenial*
Kmail-account-wizardUbuntubionic*
Kmail-account-wizardUbuntufocal*
Kmail-account-wizardUbuntugroovy*
Kmail-account-wizardUbuntuhirsute*
Kmail-account-wizardUbuntuimpish*
Kmail-account-wizardUbuntukinetic*
Kmail-account-wizardUbuntulunar*
Kmail-account-wizardUbuntumantic*
Kmail-account-wizardUbuntuoracular*
Kmail-account-wizardUbuntuplucky*
Kmail-account-wizardUbuntutrusty*

Potential Mitigations

References