CVE-2007-3275 describes a vulnerability in MailWasher Server versions prior to 2.2.1, specifically when integrated with LDAP or Active Directory. The flaw allows remote attackers to bypass authentication by exploiting improper handling of blank passwords, granting unauthorized access to any user account. This enables attackers to read spam emails stored for the compromised account. The vulnerability has a CVSS score of 7.1 (High), indicating a significant risk. It is remotely exploitable with medium attack complexity and results in a complete compromise of confidentiality (C:C) without impacting integrity or availability. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered significant attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.2.0CPE matchmatch criteria | cpe:2.3:a:mailwasher:mailwasher_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.