CVE-2020-25848: HGiga MailSherlock - Broken Authentication
HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-25848?
CVE-2020-25848 is a vulnerability found in HGiga MailSherlock that allows attackers to grant privilege remotely with a weak authentication mechanism.
How severe is CVE-2020-25848?
CVE-2020-25848 has a severity score of 9.8, which is classified as critical.
Which software versions are affected by CVE-2020-25848?
CVE-2020-25848 affects the following versions of HGiga MailSherlock: Msr45 Isherlock-antispam (up to version 4.5-130), Msr45 Isherlock-audit (up to version 4.5-143), Msr45 Isherlock-base (up to version 4.5-243), Msr45 Isherlock-user (up to version 4.5-114), Msr45 Isherlock-useradmin (up to version 4.5-122), Ssr45 Isherlock-antispam (up to version 4.5-130), Ssr45 Isherlock-audit (up to version 4.5-143), Ssr45 Isherlock-base (up to version 4.5-243), Ssr45 Isherlock-user (up to version 4.5-114), and Ssr45 Isherlock-useradmin (up to version 4.5-112).
How can I fix CVE-2020-25848?
To fix CVE-2020-25848, it is recommended to update HGiga MailSherlock to a version that includes a fix for this vulnerability.
Where can I find more information about CVE-2020-25848?
For more information about CVE-2020-25848, you can refer to the official advisory on TWNCERT's website: https://www.twcert.org.tw/tw/cp-132-4256-cfc5a-1.html