DMARC and DNS Records not found on mcuboot.com
Unknown
Vulnerability Details
Found no DMARC and DNS record on mcuboot.com .
I am also able to send an email to me on your behalf . The mail sent didnot even landed in spam folder which could make the users believe on the attacker as a legitimate person or authority.
Any attacker could do so by using any fake mailer .For exmple : Emkei's Fake mailer - emkei.cz
Screenshots have been attached for the same.
## Impact
An attacker can spoof any mcuboot.com email address .
This could allow them to appear to be a high-profile individual or company.
Actions
View on HackerOneReport Stats
- Report ID: 1186701
- State: Closed
- Substate: resolved
- Upvotes: 5