CVE-2012-4669: Isode M-Link

Medium severity, CVSS 5.8. EPSS: 0.9% chance of exploitation in the next 30 days.

M-Link R14.6 before R14.6v14 and R15.1 before R15.1v10 does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via responses for domains that were not asserted.

Affected products

  • Isode M-Link: version 14.6 only; version 15.1 only

Published 2012-08-25. Last modified 2026-06-16.