CVE-2020-26942
CRITICALAxigen Mail Server <10.3.1.27-10.3.3.1 - Privilege Escalation
Title source: llmDescription
An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a setAdminPassword operation request, subsequently setting a new arbitrary password for the admin account.
References (1)
Core 1
Core References
Scores
CVSS v3
9.1
EPSS
0.0046
EPSS Percentile
36.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-284
CWE-306
Status
published
Products (1)
axigen/axigen_mail_server
10.3.0 - 10.3.1.27
Published
Mar 21, 2024
Tracked Since
Feb 18, 2026