First published: Wed Mar 06 2024(Updated: )
An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a setAdminPassword operation request, subsequently setting a new arbitrary password for the admin account.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Axigen Mail Server for Windows | <10.3.1.27<10.3.3.1 | |
>=10.3.0<10.3.1.27 | ||
>=10.3.2.0<10.3.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-26942 has a high severity rating as it allows unauthenticated attackers to gain admin access on Axigen Mail Server.
CVE-2020-26942 affects Axigen Mail Server versions 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1.
To fix CVE-2020-26942, upgrade to Axigen Mail Server version 10.3.1.27 or 10.3.3.1 or later.
CVE-2020-26942 could lead to unauthorized administrative access, allowing attackers to manipulate sensitive configurations.
Currently, the best approach is to upgrade to a patched version, as there are no known effective workarounds.