Record summary

CVE-2023-22278 has a selected CVSS score of 5.3 (medium).

Description

m-FILTER prior to Ver.5.70R01 (Ver.5 Series) and m-FILTER prior to Ver.4.87R04 (Ver.4 Series) allows a remote unauthenticated attacker to bypass authentication and send users' unintended email when email is being sent under the certain conditions. The attacks exploiting this vulnerability have been observed.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 6, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 4, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE Listm-FILTER prior to Ver.5.70R01 (Ver.5 Series) and m-FILTER prior to Ver.4.87R04 (Ver.4 Series)affected
VulnCheckVersion data not supplied

References

2