CVE-2018-0686

HIGH

Denbun POP < 3.3p_r4.0 and Denbun IMAP < 3.3i_r4.0 - Authenticated Unrestricted Upload of Executable Files

Title source: llm
STIX 2.1

Description

Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote authenticated attackers to upload and execute any executable files via unspecified vectors.

References (3)

Core 3
Core References
Third Party Advisory third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN00344155/index.html

Scores

CVSS v3 8.8
EPSS 0.0150
EPSS Percentile 71.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (2)
neo/debun_imap < 3.3i_r4.0
neo/debun_pop < 3.3p_r4.0
Published Nov 15, 2018
Tracked Since Feb 18, 2026