logo

149 Use of an insecure channel - SMTP


Description

The configuration of the SMTP service is set to not use SSL, so confidential information traveling by this means that can be viewed without any type of encryption.


Impact

Obtain and modify confidential information sent by SMTP.


Recommendation

Deploy the application over an encrypted communication channel, use SSL secure protocols.


Threat

Unauthorized internal attacker.


Expected Remediation Time

60 minutes.


Score 4.0

Default score using CVSS 4.0. It may change depending on the context of the src.

Base 4.0

  • Attack vector: A
  • Attack complexity: H
  • Attack Requirements: N
  • Privileges required: N
  • User interaction: A
  • Confidentiality (VC): L
  • Integrity (VI): L
  • Availability (VA): N
  • Confidentiality (SC): N
  • Integrity (SI): N
  • Availability (SA): N

Threat 4.0

  • Exploit maturity: P

Requirements


Fixes


Last updated

2024/02/14