CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.9. It affects Microsoft, Exchange.
CVE
CVE-2020-15646
Severity
MEDIUM
CVSS
5.9
EPSS
0.96%
Microsoft Exchange
Original NVD Description
If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunderbird sends username and password over https to a server controlled by the attacker. This vulnerability affects Thunderbird < 68.10.0.
Related CVEs
Other vulnerabilities affecting the same vendor(s)