Weak Encryption Vulnerability in MERAK Mail Server and Icewarp Web Mail

Weak Encryption Vulnerability in MERAK Mail Server and Icewarp Web Mail

CVE-2005-0322 · HIGH Severity

AV:L/AC:L/AU:N/C:C/I:C/A:C

MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 and Mail Server 7.6.4r with Icewarp Mail Server 5.3.2 uses weak encryption in the (1) users.cfg, (2) settings.cfg, (3) users.dat or (4) user.dat files, which allows local users to extract the passwords.

Learn more about our Web App Pen Testing.