CVE-2001-1280: Medium severity Ipswitch IMail vulnerability
POP3 Server for Ipswitch IMail 7.04 and earlier generates different responses to valid and invalid user names, which allows remote attackers to determine users on the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2001-1280?
CVE-2001-1280 has a medium severity level due to the potential for user enumeration by remote attackers.
How do I fix CVE-2001-1280?
To fix CVE-2001-1280, it is recommended to upgrade to a newer version of Ipswitch IMail that no longer exhibits this vulnerability.
What does CVE-2001-1280 vulnerability involve?
CVE-2001-1280 allows remote attackers to determine valid user names by analyzing the different responses generated by the POP3 server for valid and invalid attempts.
What versions of Ipswitch IMail are affected by CVE-2001-1280?
Ipswitch IMail versions 6.0.2, 6.0.6, and 7.0.4 are affected by CVE-2001-1280.
What type of attacks can CVE-2001-1280 facilitate?
CVE-2001-1280 can facilitate user enumeration attacks, allowing attackers to identify valid accounts on the server.