VulnerabilityModified
CVE-2012-2368
Bytemark Symbiosis before Revision 1322 does not properly validate passwords, which allows remote attackers to gain access to email accounts via an arbitrary password.
MEDIUM 5.0EPSS 1.50%
Does this matter?
Lower severity and a low EPSS score (1.50%). Track it; it rarely justifies an emergency change on its own.
Description
Bytemark Symbiosis before Revision 1322 does not properly validate passwords, which allows remote attackers to gain access to email accounts via an arbitrary password.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.50% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- bytemark/symbiosis
- Source
- secalert@redhat.com
References
- http://secunia.com/advisories/48993Vendor Advisory
- http://www.openwall.com/lists/oss-security/2012/05/14/1
- http://www.openwall.com/lists/oss-security/2012/05/14/3
- https://projects.bytemark.co.uk/projects/symbiosis/repository/diff?rev=1327&rev_to=1322Exploit, Patch
- http://secunia.com/advisories/48993Vendor Advisory
- http://www.openwall.com/lists/oss-security/2012/05/14/1
- http://www.openwall.com/lists/oss-security/2012/05/14/3
- https://projects.bytemark.co.uk/projects/symbiosis/repository/diff?rev=1327&rev_to=1322Exploit, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.