QID 48241
Date Published: 2023-07-28
QID 48241: Remote Mail Service Accepting Unencrypted Credentials Detected (IMAP)
A remote management service that accepts unencrypted credentials was detected on the target host.
Services IMAP with basic auth are checked.
Sending login information without encryption can leave it vulnerable to interception by attackers on the same network using a "network sniffer." This can result in unauthorized access to sensitive data.
Solution
If possible, use alternate services that provide encryption.
Using strong cryptography, render all authentication credentials (such as passwords/phrases) unreadable during transmission.
Using strong cryptography, render all authentication credentials (such as passwords/phrases) unreadable during transmission.
Vendor References
CVEs related to QID 48241
Software Advisories
| Advisory ID | Software | Component | Link |
|---|