Stats Digest Feeds
โ† Back to all CVEs

CVE-2020-37248

MEDIUM NVD
CVSS Score 6.5
Severity MEDIUM
Published Jun 08, 2026
Vendor unknown

Description

OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account credentials in cleartext.

References