SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).
Subscriptions
No data.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 22 Mar 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended). | |
| Weaknesses | CWE-308 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-03-22T02:23:27.538Z
Reserved: 2026-03-22T02:16:55.848Z
Link: CVE-2026-33550
No data.
Status : Received
Published: 2026-03-22T03:16:01.413
Modified: 2026-03-22T03:16:01.413
Link: CVE-2026-33550
No data.
OpenCVE Enrichment
No data.
Weaknesses