CVE-2023-51765

Exp

sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports <LF>.<CR><LF> but some other popular e-mail servers do not. This is resolved in 8.18 and later versions with 'o' in srv_features.

Published: 2023-12-24 Last update: 2024-11-21 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2023-51765 is rated High Exploit Risk (62.5/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.84%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2023-51765

EDB-ID Source Kind Published Link
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2023-51765

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-12-28 0.47% 0.84% +0.37%
2 2025-12-27 0.84% 0.47% -0.37%
3 2025-11-21 0.84%

Full EPSS history (22 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2023-51765

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.3 3.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:N)
Doesn’t really leak secrets in a meaningful way.
Integrity (I:L)
Attackers could change some data, but it’s limited—not everything goes.
Availability (A:N)
Service keeps running; no real outage angle.
3.9 1.4 [email protected]

Weakness enumeration for CVE-2023-51765

OS Trackers for CVE-2023-51765

vendor priority summary link
debian not yet assigned CVE-2023-51765 not yet assigned priority: Debian including 1 source packages (sendmail), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2023-51765
redhat medium https://access.redhat.com/security/cve/CVE-2023-51765
suse medium CVE-2023-51765 severity moderate: SUSE including 14 source package names (libmilter-doc-8.15.2-150000.8.12.1, libmilter-doc-8.18.1-1.1, …), 16 product×package rows across 6 product lines (SUSE Linux Enterprise Module for Basesystem 15 SP5, SUSE Linux Enterprise Module for Legacy 12, … (6 product lines)): Fixed 16. https://www.suse.com/security/cve/CVE-2023-51765/
ubuntu medium CVE-2023-51765 medium priority: Ubuntu including 1 source packages (sendmail), 12 status rows across 12 suites (bionic, focal, jammy, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): needs-triage 5, not-affected 4, ignored 2, released 1. https://ubuntu.com/security/CVE-2023-51765

Affected software / configurations for CVE-2023-51765

Vendor Product Version Raw CPE
sendmail sendmail < 8.18.0.2 cpe:2.3:a:sendmail:sendmail:*:*:*:*:*:*:*:*
freebsd freebsd < 11.0 cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*
redhat enterprise_linux 8.0 cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
redhat enterprise_linux 9.0 cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

References for CVE-2023-51765

URL Tags
http://www.openwall.com/lists/oss-security/2023/12/24/1 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/12/25/1 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/12/26/5 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/12/29/5 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/12/30/1 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/12/30/3 Mailing List Third Party Advisory
https://access.redhat.com/security/cve/CVE-2023-51765 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2255869 Issue Tracking Third Party Advisory
https://bugzilla.suse.com/show_bug.cgi?id=1218351 Issue Tracking Patch Third Party Advisory
https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11782.html Technical Description
https://github.com/freebsd/freebsd-src/commit/5dd76dd0cc19450133aa379ce0ce4a68ae07fb39#diff-afdf514b32ac88004952c11660c57bc96c3d8b2234007c1cbd8d7ed7fd7935cc Patch
https://lists.debian.org/debian-lts-announce/2024/06/msg00004.html
https://lwn.net/Articles/956533/
https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/ Technical Description Third Party Advisory
https://www.openwall.com/lists/oss-security/2023/12/21/7 Mailing List Third Party Advisory
https://www.openwall.com/lists/oss-security/2023/12/22/7 Mailing List Third Party Advisory
https://www.youtube.com/watch?v=V8KPV96g1To Exploit
cvelogic Threat Intelligence