PT-2020-12715 · Cipplanner · Cipplanner Cipace

Published

2020-04-06

·

Updated

2021-07-21

·

CVE-2020-11599

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions CIPPlanner CIPAce version 6.80 Build 2016031401
Description An issue was discovered that allows attackers to obtain the username and password of the SMTP user through the GetDistributedPOP3 function.
Recommendations For CIPPlanner CIPAce version 6.80 Build 2016031401, consider restricting access to the GetDistributedPOP3 function until a patch is available to prevent attackers from obtaining sensitive user credentials.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11599

Affected Products

Cipplanner Cipace