CVE-2023-22278 Vulnerability Details

  /     /     /  

CVE-2023-22278 Metadata Quick Info

CVE Published: 17/01/2023 | CVE Updated: 02/08/2024 | CVE Year: 2023
Source: jpcert | Vendor: Digital Arts Inc. | Product: m-FILTER Ver.5 Series and Ver.4 Series
Status : PUBLISHED

CVE-2023-22278 Description

m-FILTER prior to Ver.5.70R01 (Ver.5 Series) and m-FILTER prior to Ver.4.87R04 (Ver.4 Series) allows a remote unauthenticated attacker to bypass authentication and send users\' unintended email when email is being sent under the certain conditions. The attacks exploiting this vulnerability have been observed.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Authentication bypass
Source: Digital Arts Inc.

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).