CRITICAL · 9.8

CVE-2020-25848

HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.

Vulnerability Description

HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
HgigaMsr45 Isherlock-Antispam< 4.5-130
HgigaMsr45 Isherlock-Audit< 4.5-143
HgigaMsr45 Isherlock-Base< 4.5-243
HgigaMsr45 Isherlock-User< 4.5-114
HgigaMsr45 Isherlock-Useradmin< 4.5-122
HgigaSsr45 Isherlock-Antispam< 4.5-130
HgigaSsr45 Isherlock-Audit< 4.5-143
HgigaSsr45 Isherlock-Base< 4.5-243
HgigaSsr45 Isherlock-User< 4.5-114
HgigaSsr45 Isherlock-Useradmin< 4.5-112

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-25848?

CVE-2020-25848 is a vulnerability with a CVSS score of 9.8 (CRITICAL). HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.

How severe is CVE-2020-25848?

CVE-2020-25848 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2020-25848?

Check the references section above for vendor advisories and patch information. Affected products include: Hgiga Msr45 Isherlock-Antispam, Hgiga Msr45 Isherlock-Audit, Hgiga Msr45 Isherlock-Base, Hgiga Msr45 Isherlock-User, Hgiga Msr45 Isherlock-Useradmin.