Exploitation Summary
CVE-2023-22278 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
m-FILTER prior to Ver.5.70R01 (Ver.5 Series) and m-FILTER prior to Ver.4.87R04 (Ver.4 Series) allows a remote unauthenticated attacker to bypass authentication and send users' unintended email when email is being sent under the certain conditions. The attacks exploiting this vulnerability have been observed.
References (1)
Core 1
Core References
Third Party Advisory
https://jvn.jp/en/jp/JVN55675303/index.html
Scores
CVSS v3
5.3
EPSS
0.0071
EPSS Percentile
48.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
VulnCheck KEV
2023-01-06
CWE
CWE-287
Status
published
Products (1)
daj/m-filter
4.0 - 4.87r04
Published
Jan 17, 2023
Tracked Since
Feb 18, 2026