← Zuruck zu CVEs
CVE-2022-37042
CRITICALCISA KEV9.8
Beschreibung
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht8/12/2022
Zuletzt geandert11/4/2025
Quellekev
Honeypot-Sichtungen0
CISA KEV
HerstellerSynacor
ProduktZimbra Collaboration Suite (ZCS)
SchwachstellennameSynacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability
KEV Aufnahmedatum2022-08-11
Behebungsfrist2022-09-01
Ransomware-NutzungKnown
Betroffene Produkte
synacor:zimbra_collaboration_suite
Schwachen (CWE)
CWE-22CWE-22
Referenzen
https://wiki.zimbra.com/wiki/Security_Center(cve@mitre.org)
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories(cve@mitre.org)
http://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html(af854a3a-2127-422b-91ae-364da2661108)
https://wiki.zimbra.com/wiki/Security_Center(af854a3a-2127-422b-91ae-364da2661108)
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories(af854a3a-2127-422b-91ae-364da2661108)
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-37042(134c704f-9b21-4f2e-91b3-4a467353bcc0)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.