CVE-2020-12714: Ciphermail Gateway

Medium severity, CVSS 5.9. EPSS: 1% chance of exploitation in the next 30 days.

An issue was discovered in CipherMail Community Gateway Virtual Appliances and Professional/Enterprise Gateway Virtual Appliances versions 1.0.1 through 4.7.1-0 and CipherMail Webmail Messenger Virtual Appliances 1.1.1 through 3.1.1-0. A Diffie-Hellman parameter of insufficient size could allow man-in-the-middle compromise of communications between CipherMail products and external SMTP clients.

Affected products

  • Ciphermail Gateway: from 1.0.1, up to and including 4.7.1-0
  • Ciphermail Webmail Messenger: from 1.1.1, up to and including 3.1.1-0

Published 2020-06-11. Last modified 2026-06-17.