Описание
A 2-Step Verification problem in Axigen 10.3.3.52 allows an attacker to access a mailbox by bypassing 2-Step Verification when they try to add an account to any third-party webmail service (or add an account to Outlook or Gmail, etc.) with IMAP or POP3 without any verification code.
Ссылки
- Third Party Advisory
- Third Party Advisory
- Technical DescriptionVendor Advisory
- Vendor Advisory
- Third Party Advisory
- Third Party Advisory
- Technical DescriptionVendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:axigen:axigen_mail_server:10.3.3.52:*:*:*:*:*:*:*
EPSS
Процентиль: 72%
0.00704
Низкий
9.8 Critical
CVSS3
Дефекты
NVD-CWE-Other
CWE-276
Связанные уязвимости
CVSS3: 9.8
github
около 3 лет назад
A 2-Step Verification problem in Axigen 10.3.3.52 allows an attacker to access a mailbox by bypassing 2-Step Verification when they try to add an account to any third-party webmail service (or add an account to Outlook or Gmail, etc.) with IMAP or POP3 without any verification code.
EPSS
Процентиль: 72%
0.00704
Низкий
9.8 Critical
CVSS3
Дефекты
NVD-CWE-Other
CWE-276