SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-4620

The useredit_account.wdm module in Alt-N WebAdmin 3.2.5 running with MDaemon 9.0.6, and possibly earlier versions, allows remote authenticated domain administrators to gain privileges and obtain access to the system mail queue by modifying the mailbox…

MEDIUM 4.6EPSS 1.19%

Does this matter?

Lower severity and a low EPSS score (1.19%). Track it; it rarely justifies an emergency change on its own.

Description

The useredit_account.wdm module in Alt-N WebAdmin 3.2.5 running with MDaemon 9.0.6, and possibly earlier versions, allows remote authenticated domain administrators to gain privileges and obtain access to the system mail queue by modifying the mailbox of the MDaemon user account to use the mailbox of another account.

CVSS 2.0
4.6 MEDIUMAV:N/AC:H/Au:S/C:P/I:P/A:P
EPSS
1.19% probability · 66th percentile
CISA KEV
Not listed
Affected
alt-n/webadmin
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.