QID 48244
Date Published: 2023-07-28
QID 48244: Remote Mail Service Accepting Unencrypted Credentials Detected (SMTP)
A remote management service that accepts unencrypted credentials was detected on the target host.
Services SMTP with basic auth are checked.
Sending login information without encryption can leave it vulnerable to interception by attackers on the same network using a "network sniffer." This can result in unauthorized access to sensitive data.
Solution
If possible, use alternate services that provide encryption.
Using strong cryptography, render all authentication credentials (such as passwords/phrases) unreadable during transmission.
Using strong cryptography, render all authentication credentials (such as passwords/phrases) unreadable during transmission.
Vendor References
CVEs related to QID 48244
Software Advisories
| Advisory ID | Software | Component | Link |
|---|