Description
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
Low
Affected products
- Synacor / zimbra_collaboration_suite10.1.20
- Zimbra / Collaboration0 – 10.1.20
Exploits & proofs of concept
- nucleiZimbra Collaboration Suite < 10.1.20 - OS Command Injectionby 0x_Akoko,ritikchaddha
News coverage
- Exploited Zimbra Flaw Highlights Shrinking Window to PatchDark Reading · 3d ago
- Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code ExecutionThe Hacker News · 7d ago
References
Updated 6m ago · 8 sources