An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a setAdminPassword operation request, subsequently setting a new arbitrary password for the admin account.
Metrics
Affected Vendors & Products
References
History
Wed, 05 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Axigen
Axigen axigen Mail Server |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:axigen:axigen_mail_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Axigen
Axigen axigen Mail Server |
Status: PUBLISHED
Assigner: mitre
Published: 2024-03-06T00:00:00
Updated: 2024-08-05T14:32:33.326Z
Reserved: 2020-10-10T00:00:00
Link: CVE-2020-26942
Updated: 2024-08-04T16:03:23.061Z
Status : Analyzed
Published: 2024-03-21T02:36:18.443
Modified: 2025-03-05T18:25:53.837
Link: CVE-2020-26942
No data.
ReportizFlow