VulnerabilityModified
CVE-2000-1002
POP3 daemon in Stalker CommuniGate Pro 3.3.2 generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to determine valid email addresses on the server for SPAM attacks.
MEDIUM 5.0EPSS 7.49%
Does this matter?
Lower severity and a low EPSS score (7.49%). Track it; it rarely justifies an emergency change on its own.
Description
POP3 daemon in Stalker CommuniGate Pro 3.3.2 generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to determine valid email addresses on the server for SPAM attacks.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 7.49% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- stalker/communigate pro
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/archive/1/139523Vendor Advisory
- http://www.securityfocus.com/bid/1792Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5363
- http://www.securityfocus.com/archive/1/139523Vendor Advisory
- http://www.securityfocus.com/bid/1792Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5363
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.