PT-2023-19046 · Microsoft+1 · Outlook+1
Soheil Samanabadi
·
Published
2023-01-13
·
Updated
2025-04-07
·
CVE-2023-23566
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Axigen version 10.3.3.52
Description
A 2-Step Verification issue allows an attacker to access a mailbox by bypassing 2-Step Verification when trying to add an account to any third-party webmail service with IMAP or POP3 without any verification code. This can occur when adding an account to services like Outlook or Gmail.
Recommendations
For Axigen version 10.3.3.52, consider disabling the IMAP and POP3 services until a patch is available to prevent bypassing 2-Step Verification. Restrict access to adding accounts to third-party webmail services to minimize the risk of exploitation.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gmail
Outlook