# CVE-2020-37248

## Summary

- **CVE ID:** CVE-2020-37248
- **Severity:** MEDIUM
- **CVSS Score:** 6.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N)
- **CWE:** CWE-348
- **Published:** Jun 8, 2026
- **Last Modified:** Jun 8, 2026

## Description

OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account credentials in cleartext.

## Affected Products

- OfflineIMAP — OfflineIMAP (0)

## References

- [CNA](https://github.com/OfflineIMAP/offlineimap3/commit/46505c53ef995455d66c685f9ec3ff6ea93dbb74)
- [CNA](https://github.com/OfflineIMAP/offlineimap3/issues/222)
- [CNA](https://github.com/OfflineIMAP/offlineimap/issues/669)
- [CNA](https://pypi.org/project/offlineimap/#history)
- [CVE](http://www.openwall.com/lists/oss-security/2026/06/08/3)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.19%
- **EPSS Percentile:** 8.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._