Medium severity4.8NVD Advisory· Published Aug 20, 2020· Updated Jun 17, 2026
CVE-2020-12618
CVE-2020-12618
Description
eM Client before 7.2.33412.0 automatically imported S/MIME certificates and thereby silently replaced existing ones. This allowed a man-in-the-middle attacker to obtain an email-validated S/MIME certificate from a trusted CA and replace the public key of the entity to be impersonated. This enabled the attacker to decipher further communication. The entire attack could be accomplished by sending a single email.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- eM Client/eM Clientdescription
Patches
Vulnerability mechanics
References
2- www.emclient.com/release-historynvdRelease NotesVendor Advisory
- www.nds.ruhr-uni-bochum.de/media/nds/veroeffentlichungen/2020/08/15/mailto-paper.pdfnvdThird Party Advisory
News mentions
0No linked articles in our index yet.