Description
HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update MailSherlock MSR45/SSR45 Module to: iSherlock-base-4.5-243.i386.rpm iSherlock-user-4.5-114.i386.rpm iSherlock-useradmin-4.5-122.i386.rpm iSherlock-audit-4.5-143.i386.rpm iSherlock-antispam-4.5-130.i386.rpm
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-18481 | HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-4256-cfc5a-1.html |
|
History
No history.
Subscriptions
Hgiga
Subscribe
Msr45 Isherlock-antispam
Subscribe
Msr45 Isherlock-audit
Subscribe
Msr45 Isherlock-base
Subscribe
Msr45 Isherlock-user
Subscribe
Msr45 Isherlock-useradmin
Subscribe
Ssr45 Isherlock-antispam
Subscribe
Ssr45 Isherlock-audit
Subscribe
Ssr45 Isherlock-base
Subscribe
Ssr45 Isherlock-user
Subscribe
Ssr45 Isherlock-useradmin
Subscribe
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-17T00:11:14.724Z
Reserved: 2020-09-23T00:00:00.000Z
Link: CVE-2020-25848
No data.
Status : Modified
Published: 2020-12-31T08:15:13.410
Modified: 2024-11-21T05:18:53.930
Link: CVE-2020-25848
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD