CVE-2023-23566
Summary
| CVE | CVE-2023-23566 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-01-13 04:15:00 UTC |
| Updated | 2023-01-26 17:47:00 UTC |
| Description | A 2-Step Verification problem in Axigen 10.3.3.52 allows an attacker to access a mailbox by bypassing 2-Step Verification when they try to add an account to any third-party webmail service (or add an account to Outlook or Gmail, etc.) with IMAP or POP3 without any verification code. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Axigen | Axigen Mail Server | 10.3.3.52 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 2-Step Verification (Two Factor Authentication) for WebMail | Axigen Documentation | MISC | www.axigen.com | |
| Axigen Mail server 10.3.3.52 Two-Step verification · Issue #1 · umz-cert/vulnerabilities · GitHub | MISC | github.com | |
| vulnerabilitys/Axigen Mail Server 10.3.3.52 2-Step verification at patch-1 · umz-cert/vulnerabilitys · GitHub | MISC | github.com | |
| Download Mail Server | Axigen | MISC | www.axigen.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.