SMTP Service Cleartext Login Permitted

This script is Copyright (C) 2011-2017 Tenable Network Security, Inc.

Synopsis :

The remote mail server allows cleartext logins.

Description :

The remote host is running an SMTP server that advertises that it
allows cleartext logins over unencrypted connections. An attacker may
be able to uncover user names and passwords by sniffing traffic to the
server if a less secure authentication mechanism (i.e. LOGIN or
PLAIN) is used.

See also :

Solution :

Configure the service to support less secure authentication
mechanisms only over an encrypted channel.

Risk factor :

Low / CVSS Base Score : 2.6

Family: SMTP problems

Nessus Plugin ID: 54582 ()

Bugtraq ID:


Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now