PT-2025-31526 · Exagrid · Exagrid Ex10

0Xsu3Ks

·

Published

2025-07-31

·

Updated

2025-07-31

·

CVE-2025-29557

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ExaGrid EX10 versions 6.3 through 7.0.1.P08
Description The software is susceptible to incorrect access control. Users with operator-level privileges can retrieve SMTP credentials, including plaintext passwords, by issuing an HTTP request to the MailConfiguration API endpoint.
Recommendations Restrict access to the MailConfiguration API endpoint for operator-level users.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-29557

Affected Products

Exagrid Ex10