Advertisement






ProtonMail Reading Encrypted Data Logical Error

CVE Category Price Severity
CVE-2021-3004 CWE-409 Not specified Critical
Author Risk Exploitation Type Date
Unknown High Remote 2020-02-19
CPE
cpe:cpe:/a:protonmail:email_service:unknown
CVSS EPSS EPSSP
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2020020093

Below is a copy:

ProtonMail Reading Encrypted Data Logical Error
Description : Due to this error, we can read the topics of the encrypted data and read some information.

Author : Gaddar
Team : SiyahBayrak

PoC;
- Create ProtonMail account.
- Send post your mail.
- Send a mail to an email address(ProtonMail) you have created from a different email address.
- Now post readable. (Not Encrypted)
- Log out ProtonMail account.
- Reset password.
- Accept steps.
- Login your ProtonMail account after reset password. Authorities tell you that your old mail will be encrypted.
- You can read post titles but you're cannot read post details. But this sometimes dangerous. Please look example :)

Ex : https://ibb.co/RDWjFs0

My social accounts ;
Instagram.com/pt.php
Facebook.com/ptsec
Twitter.com/ptguvenlik
Youtube.com/c/gaddarsec

My Teammates : DeadLy-Warrior - StabilBey - Diablo

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum