CVE-2018-0682
(Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) does not properly manage sessions, which allows remote attackers to read/send mail or change the configuration via unspecified vectors.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.76%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) does not properly manage sessions, which allows remote attackers to read/send mail or change the configuration via unspecified vectors.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.76% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- neo/debun imap · neo/debun pop
- Source
- vultures@jpcert.or.jp
References
- http://jvn.jp/en/jp/JVN00344155/index.htmlThird Party Advisory
- https://www.denbun.com/en/imap/support/security/181003.htmlVendor Advisory
- https://www.denbun.com/en/pop/support/security/181003.htmlVendor Advisory
- http://jvn.jp/en/jp/JVN00344155/index.htmlThird Party Advisory
- https://www.denbun.com/en/imap/support/security/181003.htmlVendor Advisory
- https://www.denbun.com/en/pop/support/security/181003.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.