MailEnable versions prior to 10.54 contain a cleartext storage of credentials vulnerability that can lead to local credential compromise and account takeover. The product stores user and administrative passwords in plaintext within AUTH.TAB with overly permissive filesystem access. A local authenticated user with read access to this file can recover all user passwords and super-admin credentials, then use them to authenticate to MailEnable services such as POP3, SMTP, or the webmail interface, enabling unauthorized mailbox access and administrative control.
Metrics
Affected Vendors & Products
References
History
Thu, 11 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mailenable
Mailenable mailenable |
|
| Vendors & Products |
Mailenable
Mailenable mailenable |
Wed, 10 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Dec 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MailEnable versions prior to 10.54 contain a cleartext storage of credentials vulnerability that can lead to local credential compromise and account takeover. The product stores user and administrative passwords in plaintext within AUTH.TAB with overly permissive filesystem access. A local authenticated user with read access to this file can recover all user passwords and super-admin credentials, then use them to authenticate to MailEnable services such as POP3, SMTP, or the webmail interface, enabling unauthorized mailbox access and administrative control. | |
| Title | MailEnable < 10.54 Cleartext Credential Storage in AUTH.TAB | |
| Weaknesses | CWE-312 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-10T18:24:13.947Z
Updated: 2025-12-10T18:55:49.300Z
Reserved: 2025-04-15T19:15:22.600Z
Link: CVE-2025-34427
Updated: 2025-12-10T18:55:43.057Z
Status : Received
Published: 2025-12-10T19:16:13.403
Modified: 2025-12-10T19:16:13.403
Link: CVE-2025-34427
No data.