LiveActive security incident?Get immediate response
CVE Record

CVE-2022-48521: An issue was discovered in OpenDKIM through 2.10.3, and 2.11.x through 2.11.0-Beta2.

An issue was discovered in OpenDKIM through 2.10.3, and 2.11.x through 2.11.0-Beta2. It fails to keep track of ordinal numbers when removing fake Authentication-Results header fields, which allows a remote attacker to craft an e-mail message with a fake sender address such that programs that rely on Authentication-Results from OpenDKIM will treat the message as having a valid DKIM signature when in fact it has none.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

OpenDKIM can be fooled while handling fake Authentication-Results email headers. A remote sender may craft an email that makes downstream systems believe OpenDKIM validated a DKIM signature, even when no valid signature exists. The main business risk is spoofed email gaining misplaced trust, supporting phishing or fraud workflows.

Executive priority

Prioritize remediation for internet-facing mail systems and environments with high phishing exposure. This issue undermines email authentication trust, which can affect fraud prevention and executive impersonation defenses, but the sources do not indicate active exploitation or host compromise.

Technical view

Affected OpenDKIM versions through 2.10.3 and 2.11.x through 2.11.0-Beta2 fail to track ordinal numbers correctly when removing fake Authentication-Results fields. This can leave consumers of OpenDKIM Authentication-Results with a false DKIM-valid result for a message with a fake sender and no valid DKIM signature.

Likely exposure

Exposure is most likely on mail infrastructure running affected OpenDKIM versions and using its Authentication-Results output to drive filtering, trust decisions, banners, routing, or downstream automation.

Exploitation context

The CVE describes remote exploitation through crafted email. The provided sources do not show CISA KEV listing or confirmed active exploitation. Public evidence is enough to treat this as a mail trust bypass, not as server code execution.

Researcher notes

The key behavior is incorrect ordinal tracking during removal of fake Authentication-Results headers. Validation should focus on affected OpenDKIM versions and downstream consumers that accept its output as authoritative. Source data lacks CVSS, CWE, and complete upstream fix details.

Mitigation direction

  • Apply the Debian DLA 3680-1 opendkim security update where applicable.
  • Check OpenDKIM and distribution vendor guidance for fixed packages.
  • Identify and replace OpenDKIM versions through 2.10.3 and affected 2.11 beta builds.
  • Review systems that trust OpenDKIM Authentication-Results for automated decisions.
  • Ensure downstream mail tools trust only locally generated authentication results.

Validation and detection

  • Inventory mail gateways and relays for installed OpenDKIM versions.
  • Confirm whether OpenDKIM Authentication-Results drives filtering, routing, or user-visible trust indicators.
  • Verify applicable vendor security updates are installed on Debian LTS systems.
  • Review mail-processing logs for suspicious sender-authentication mismatches.
  • Document any remaining affected hosts and compensating controls.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2022-48521 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.