Unspecified vulnerability in a cryptographic feature in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Enterprise Edition before 1.21 leads to "weakened authentication security" with unknown impact and attack vectors. NOTE: due to lack of details, it is not clear whether this is the same as CVE-2006-1792.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://www.mailenable.com/professionalhistory.asp | vendor advisory |
http://www.mailenable.com/enterprisehistory.asp | vendor advisory |
http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1359.html | mailing list vendor advisory |
http://www.mailenable.com/standardhistory.asp | vendor advisory |