CVE-2024-45519

Kritisch10.0Veröffentlicht am 2. Oktober 2024

Der postjournal-Dienst in Zimbra Collaboration (ZCS) vor 8.8.15 Patch 46, 9 vor 9.0.0 Patch 41, 10 vor 10.0.9 und 10.1 vor 10.1.1 erlaubt nicht authentifizierten Benutzern manchmal die Ausführung von Befehlen.

Aktiv ausgenutzt

  • Seit dem 3. Okt. 2024 im CISA-Katalog ausgenutzter Schwachstellen
  • US-Bundesbehörden müssen sie bis zum 24. Okt. 2024 beheben (BOD 22-01)
  • Angegriffen 2 Tage bevor die Schwachstelle öffentlich wurde

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Quelle: CISA KEV · 9. Okt. 2025 3. Apr. 2025 9. Okt. 2024 3. Okt. 2024 1. Okt. 2024 1. Okt. 2024

CVSS-Score10.0 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Schwachstellentyp (CWE)CWE-78
Herstellersynacor

Betroffene Produkte

HerstellerProduktVersionen
synacorzimbra collaboration suite< 8.8.15

Verwandte Artikel

This product uses the NVD API but is not endorsed or certified by the NVD.

Die technische Beschreibung ist unsere Übersetzung des englischen NVD-Originaltexts.

CVE-Datenbank