CVE-2000-0301: Medium severity Ipswitch IMail vulnerability
Ipswitch IMAIL server 6.02 and earlier allows remote attackers to cause a denial of service via the AUTH CRAM-MD5 command.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the AUTH CRAM-MD5 authentication mechanism in the IMail server configuration to prevent exploitation via the AUTH CRAM-MD5 command.
Ipswitch IMail AUTH CRAM-MD5 = disabled - Compensating control
If disabling AUTH CRAM-MD5 is not immediately possible, restrict remote access to the IMail service (SMTP/management ports) at the network perimeter (firewall/ACL) to only trusted IPs and monitoring systems to reduce exposure to remote attackers.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0301?
CVE-2000-0301 is considered a moderate severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2000-0301?
To fix CVE-2000-0301, upgrade the Ipswitch IMAIL server to a version later than 6.2.
Which versions of Ipswitch IMAIL are affected by CVE-2000-0301?
CVE-2000-0301 affects Ipswitch IMAIL versions 6.02 and earlier, as well as multiple 5.x versions.
What type of attack does CVE-2000-0301 allow?
CVE-2000-0301 allows remote attackers to perform a denial of service via the AUTH CRAM-MD5 command.
Is there a workaround for CVE-2000-0301?
No specific workaround is recommended for CVE-2000-0301, so upgrading to a fixed version is advised.