PT-2020-12715 · Cipplanner · Cipplanner Cipace
Published
2020-04-06
·
Updated
2021-07-21
·
CVE-2020-11599
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CIPPlanner CIPAce version 6.80 Build 2016031401
Description
An issue was discovered that allows attackers to obtain the username and password of the SMTP user through the GetDistributedPOP3 function.
Recommendations
For CIPPlanner CIPAce version 6.80 Build 2016031401, consider restricting access to the GetDistributedPOP3 function until a patch is available to prevent attackers from obtaining sensitive user credentials.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cipplanner Cipace