CVE-2020-25848: Hgiga MSR45 Isherlock-Antispam
Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.
HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.
Affected products
- Hgiga MSR45 Isherlock-Antispam: before 4.5-130 (fixed in 4.5-130)
- Hgiga MSR45 Isherlock-Audit: before 4.5-143 (fixed in 4.5-143)
- Hgiga MSR45 Isherlock-Base: before 4.5-243 (fixed in 4.5-243)
- Hgiga MSR45 Isherlock-User: before 4.5-114 (fixed in 4.5-114)
- Hgiga MSR45 Isherlock-Useradmin: before 4.5-122 (fixed in 4.5-122)
- Hgiga SSR45 Isherlock-Antispam: before 4.5-130 (fixed in 4.5-130)
- Hgiga SSR45 Isherlock-Audit: before 4.5-143 (fixed in 4.5-143)
- Hgiga SSR45 Isherlock-Base: before 4.5-243 (fixed in 4.5-243)
- Hgiga SSR45 Isherlock-User: before 4.5-114 (fixed in 4.5-114)
- Hgiga SSR45 Isherlock-Useradmin: before 4.5-112 (fixed in 4.5-112)
Published 2020-12-31. Last modified 2026-06-17.