Impact
Stack-based buffer overflow in the web service of Canon Marketing Japan Inc.’s GUARDIANWALL MailSuite and Mail Security Cloud allows a remote attacker to send a crafted request and execute arbitrary code. Triggered when the product runs pop3wallpasswd with the grdnwww user account, the flaw maps to CWE‑121 and could compromise the confidentiality, integrity, and availability of the host if the privileged user has broad access.
Affected Systems
Canon Marketing Japan Inc.’s GUARDIANWALL Mail Security Cloud (SaaS version) and GUARDIANWALL MailSuite (On‑premises version) are affected. Specific versions are not disclosed, so all current deployments of these products should be checked for the presence of the vulnerability and for any available updates.
Risk and Exploitability
The CVSS score of 9.3 classifies this flaw as critical. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, but the high exploitation potential is reflected in the score. The attack vector is remote over HTTP/S to the product’s web service. If exploited, arbitrary code runs with the privileges of the grdnwww user, allowing attackers to modify configurations, exfiltrate data, or install additional malware. The lack of an official patch in the advisory means that administrators must rely on configuration hardening and network segmentation to reduce exposure.
OpenCVE Enrichment