A 2-Step Verification problem in Axigen 10.3.3.52 allows an attacker to access a mailbox by bypassing 2-Step Verification when they try to add an account to any third-party webmail service (or add an account to Outlook or Gmail, etc.) with IMAP or POP3 without any verification code.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://github.com/umz-cert/vulnerabilities/issues/1 | third party advisory |
https://github.com/umz-cert/vulnerabilitys/blob/patch-1/Axigen%20Mail%20Server%2010.3.3.52%202-Step%20verification | third party advisory |
https://www.axigen.com/mail-server/download/ | vendor advisory |
https://www.axigen.com/documentation/2-step-verification-two-factor-authentication-for-webmail-p69140479 | technical description vendor advisory |