CVE-2023-23566
A 2-Step Verification problem in Axigen 10.3.3.52 allows an attacker to access a mailbox by bypassing 2-Step Verification when they try to add an account to any third-party webmail service (or add an account to Outlook or Gmail, etc.) with IMAP or POP3…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.95%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A 2-Step Verification problem in Axigen 10.3.3.52 allows an attacker to access a mailbox by bypassing 2-Step Verification when they try to add an account to any third-party webmail service (or add an account to Outlook or Gmail, etc.) with IMAP or POP3 without any verification code.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.95% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-276
- Affected
- axigen/axigen mail server
- Source
- cve@mitre.org
References
- https://github.com/umz-cert/vulnerabilities/issues/1Third Party Advisory
- https://github.com/umz-cert/vulnerabilitys/blob/patch-1/Axigen%20Mail%20Server%2010.3.3.52%202-Step%20verificationThird Party Advisory
- https://www.axigen.com/documentation/2-step-verification-two-factor-authentication-for-webmail-p69140479Technical Description, Vendor Advisory
- https://www.axigen.com/mail-server/download/Vendor Advisory
- https://github.com/umz-cert/vulnerabilities/issues/1Third Party Advisory
- https://github.com/umz-cert/vulnerabilitys/blob/patch-1/Axigen%20Mail%20Server%2010.3.3.52%202-Step%20verificationThird Party Advisory
- https://www.axigen.com/documentation/2-step-verification-two-factor-authentication-for-webmail-p69140479Technical Description, Vendor Advisory
- https://www.axigen.com/mail-server/download/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.