CVE-2018-0681

CRITICAL

Denbun POP < 3.3p_r4.0 and Denbun IMAP < 3.3i_r4.0 - Use of Hard-coded Credentials

Title source: llm
STIX 2.1

Description

Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which may allow remote attackers to login to the Management page and change the configuration.

References (3)

Core 3
Core References
Third Party Advisory third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN00344155/index.html

Scores

CVSS v3 9.8
EPSS 0.0167
EPSS Percentile 73.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (2)
neo/debun_imap < 3.3i_r4.0
neo/debun_pop < 3.3p_r4.0
Published Nov 15, 2018
Tracked Since Feb 18, 2026