Описание
SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor.
EPSS
Процентиль: 38%
0.0045
Низкий
Дефекты
CWE-287
Связанные уязвимости
github
12 дней назад
SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor.
EPSS
Процентиль: 38%
0.0045
Низкий
Дефекты
CWE-287