截至 2026 年 4 月,N-able Mail Assure 存在一处设计层面的授权缺陷,允许已认证的 SMTP 用户使用属于其他租户的 MAIL FROM 地址发送出站邮件。当客户端通过 SMTP TCP 端口连接并使用有效凭证执行 SMTP AUTH 认证时,服务器会接受任意发件人域,而未强制实施域与账户之间的绑定关系。因此,来自任意租户的攻击者可以冒充其他租户的域发送邮件,这些邮件能够通过 SPF(发件人策略框架)和 DMARC(基于域的邮件认证、报告和一致性)验证。 注:N-able 的立场是,该行为是
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| N-able | Mail Assure | 0 ~ April 2026 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet