CISA Adds Zimbra Email Vulnerability to its Exploited Vulnerabilities Catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-27924 | Unauthenticated Memcache Command Injection in Synacor Zimbra Collaboration Suite Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 pass unauthenticated network input to memcache without escaping, allowing a remote attacker to inject arbitrary memcache commands (CWE-74). By sending crafted requests to Zimbra's exposed web/mail services, an attacker can poison the cache and overwrite arbitrary cached entries — a high-severity integrity impact that, in reported campaigns, has been used to tamper with cached data and steal users' login credentials. Any organization running unpatched ZCS 8.8.15 or 9.0 is affected, including the enterprise, ISP, and government mail deployments that make up Zimbra's installed base. Exploitation is ongoing and widespread: the flaw was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-08-04 after mass exploitation, with known ransomware use, and EPSS assigns an 85.4% probability of exploitation within 30 days (100th percentile). Do: Apply the latest Zimbra patches for the 8.8.15 and 9.0 branches per the vendor's instructions, as required by CISA's KEV entry. As an interim mitigation, restrict memcache access (default TCP port 11211) so it cannot be reached through untrusted interfaces or the exposed mail/web services. Given known ransomware use, prioritize internet-facing Zimbra servers and review mail/web logs for signs of memcache command injection or cache tampering. | 7.5 | 85% | KEV ransomware |
| mass≈50,000–100,000 internet-exposed Zimbra servers; total user base plausibly in the millions |
Full article222 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananAug 05, 2022
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a recently disclosed high-severity vulnerability in the Zimbra email suite to its Known Exploited Vulnerabilities Catalog, citing evidence of active exploitation.
The issue in question is CVE-2022-27924 (CVSS score: 7.5), a command injection flaw in the platform that could lead to the execution of arbitrary Memcached commands and theft of sensitive information.
"Zimbra Collaboration (ZCS) allows an attacker to inject memcached commands into a targeted instance which causes an overwrite of arbitrary cached entries," CISA said.
Specifically, the bug relates to a case of insufficient validation of user input that, if successfully exploited, could enable attackers to steal cleartext credentials from users of targeted Zimbra instances.
The issue was disclosed by SonarSource in June, with patches released by Zimbra on May 10, 2022, in versions 8.8.15 P31.1 and 9.0.0 P24.1.
CISA hasn't shared technical details of the attacks that exploit the vulnerability in the wild and has yet to attribute it to a certain threat actor.
In the light of active exploitation of the flaw, users are recommended to apply the updates to the software to reduce their exposure to potential cyberattacks.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/08/cisa-adds-zimbra-email-vulnerability-to.html