ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control in the MailConfiguration API endpoint, where users with operator-level privileges can issue an HTTP request to retrieve SMTP credentials, including plaintext passwords.
Metrics
Affected Vendors & Products
References
History
Thu, 31 Jul 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-284 | |
Metrics |
cvssV3_1
|
Thu, 31 Jul 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control in the MailConfiguration API endpoint, where users with operator-level privileges can issue an HTTP request to retrieve SMTP credentials, including plaintext passwords. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-07-31T00:00:00.000Z
Updated: 2025-07-31T19:48:10.537Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-29557

Updated: 2025-07-31T19:48:03.290Z

Status : Awaiting Analysis
Published: 2025-07-31T15:15:36.110
Modified: 2025-07-31T20:15:32.113
Link: CVE-2025-29557

No data.