CVE-2010-2580

UnknownEPSS 3.84%

Last modified

CVE-2010-2580 is a vulnerability of currently unknown severity. The SMTP service (MESMTPC.exe) in MailEnable 3.x and 4.25 does not properly perform a length check, which allows remote attackers to cause a denial of service (crash) via a long (1) email address in the MAIL FROM command, or (2) domain name in the RCPT TO command, which triggers an "unhandled invalid parameter error.". EPSS estimates a 3.84% chance of exploitation in the next 30 days.

Description

The SMTP service (MESMTPC.exe) in MailEnable 3.x and 4.25 does not properly perform a length check, which allows remote attackers to cause a denial of service (crash) via a long (1) email address in the MAIL FROM command, or (2) domain name in the RCPT TO command, which triggers an "unhandled invalid parameter error."

Metrics

EPSS Probability
3.84%

88.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
MailenableMailenable<= 4.25
MailenableMailenable4.0
MailenableMailenable4.1
MailenableMailenable4.01
MailenableMailenable4.11
MailenableMailenable4.12
MailenableMailenable4.13
MailenableMailenable4.14
MailenableMailenable4.15
MailenableMailenable4.16
MailenableMailenable4.17
MailenableMailenable4.22
MailenableMailenable4.23
MailenableMailenable4.24
MailenableMailenable3.61
MailenableMailenable3.62
MailenableMailenable3.63
MailenableMailenable3.0
MailenableMailenable3.01
MailenableMailenable3.02
MailenableMailenable3.03
MailenableMailenable3.04
MailenableMailenable3.5
MailenableMailenable3.6
MailenableMailenable3.10
MailenableMailenable3.11
MailenableMailenable3.12
MailenableMailenable3.13
MailenableMailenable3.14
MailenableMailenable3.51
MailenableMailenable3.52
MailenableMailenable3.53

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2010-2580?
The SMTP service (MESMTPC.exe) in MailEnable 3.x and 4.25 does not properly perform a length check, which allows remote attackers to cause a denial of service (crash) via a long (1) email address in the MAIL FROM command, or (2) domain name in the RCPT TO command, which triggers an "unhandled invalid parameter error."
How severe is CVE-2010-2580?
Severity scoring for CVE-2010-2580 is pending analysis. The EPSS model estimates a 3.84% probability of exploitation in the next 30 days.
How do I fix CVE-2010-2580?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2010-2580?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST