CVE-2006-0130
Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier allows remote attackers to attempt authentication with an unlimited number of user account names and passwords without denying connections, limiting…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.40%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier allows remote attackers to attempt authentication with an unlimited number of user account names and passwords without denying connections, limiting the rate of connections, or locking out an account.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.40% probability · 71th percentile
- CISA KEV
- Not listed
- Affected
- rockliffe/mailsite
- Source
- cve@mitre.org
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040970.htmlVendor Advisory
- http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txtVendor Advisory
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040970.htmlVendor Advisory
- http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txtVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.