ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Zimbra Warns of Critical Zero-Day Flaw in Email Software Amid Active Exploitation

criticalExploit / PoC exploited in the wildimportance 60CVE-2023-20214CVE-2023-37580

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-20214
A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to ga

A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance. This vulnerability is due to insufficient request validation when using the REST API feature. An attacker could exploit this vulnerability by sending a crafted API request to an affected vManage instance. A successful exploit could allow the attacker to retrieve information from and send information to the configuration of the affected Cisco vManage instance. This vulnerability only affects the REST API and does not affect the web-based management interface or the CLI.

NVD description · AI analysis pending
9.1<1%
  • cisco catalyst sd-wan manager
  • cisco sd-wan vmanage
CVE-2023-37580
Stored Cross-Site Scripting (XSS) in Synacor Zimbra Collaboration Suite (ZCS)

CVE-2023-37580 is a cross-site scripting flaw (CWE-79) in Synacor Zimbra Collaboration Suite's webmail interface, publicly described as a stored XSS in which attacker-supplied content persists and executes in victims' browsers. An attacker delivers crafted content (typically a malicious email or message) that, when viewed by a user in the Zimbra webmail client, runs attacker-controlled JavaScript within that user's authenticated session. Successful execution impacts the confidentiality and integrity of the victim's mailbox: the attacker can steal session cookies or credentials, read or alter mail, and act as the user. Any organization running a vulnerable ZCS release is affected, including self-hosted on-premises deployments and providers hosting Zimbra webmail for customers. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-07-27, confirming exploitation in the wild (ransomware association unknown), while no public proof-of-concept is posted, CVSS is not yet scored, and EPSS assigns a 46.7% probability of exploitation within 30 days (99th percentile).

Do: Apply the latest ZCS patch release addressing CVE-2023-37580 per the Synacor/Zimbra security advisory, as CISA's required action directs, or discontinue use of the affected deployment if mitigation is unavailable; because the flaw is on the KEV list, prioritize internet-facing webmail servers. While patching is pending, restrict webmail exposure (VPN or IP allowlisting) and review webmail and mail-delivery logs for signs of exploitation. Confirm the installed ZCS version and applied patch level against the vendor advisory, since this dataset does not list fixed version numbers.

6.147% KEV
  • Synacor Zimbra Collaboration Suite (ZCS)
masstens of thousands of internet-exposed Zimbra servers (order of 10,000–100,000) serving millions of mailboxes in aggregate (estimate)

Indicators of compromiseAll →

TypeIndicatorContext
ipv420.10.1.2dressed in versions 20.6.3.4, 20.6.4.2, 20.6.5.5, 20.9.3.2, 20.10.1.2, and 20.11.1.2. The networking equipment major said it's no
ipv420.6.3.4instance." The vulnerability has been addressed in versions 20.6.3.4, 20.6.4.2, 20.6.5.5, 20.9.3.2, 20.10.1.2, and 20.11.1.2. Th
ipv420.6.4.2The vulnerability has been addressed in versions 20.6.3.4, 20.6.4.2, 20.6.5.5, 20.9.3.2, 20.10.1.2, and 20.11.1.2. The networki
ipv420.6.5.5rability has been addressed in versions 20.6.3.4, 20.6.4.2, 20.6.5.5, 20.9.3.2, 20.10.1.2, and 20.11.1.2. The networking equipme
ipv420.9.3.2as been addressed in versions 20.6.3.4, 20.6.4.2, 20.6.5.5, 20.9.3.2, 20.10.1.2, and 20.11.1.2. The networking equipment major s
Full article395 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJul 14, 2023Email Security / Vulnerability

Zimbra has warned of a critical zero-day security flaw in its email software that has come under active exploitation in the wild.

"A security vulnerability in Zimbra Collaboration Suite Version 8.8.15 that could potentially impact the confidentiality and integrity of your data has surfaced," the company said in an advisory.

It also said that the issue has been addressed and that it's expected to be delivered in the July patch release. Additional specifics about the flaw are currently unavailable, although Zimbra said it fixed the issue through input sanitization.

In the interim, it is urging customers to apply a manual fix to eliminate the attack vector -

  1. Take a backup of the file /opt/zimbra/jetty/webapps/zimbra/m/momoveto
  2. Edit this file and go to line number 40
  3. Update the parameter value as: <input name="st" type="hidden" value="${fn:escapeXml(param.st)}"/>
  4. Before the update, the line appeared as: <input name="st" type="hidden" value="${param.st}"/>

While the company did not disclose details of active exploitation, Google Threat Analysis Group (TAG) researcher Maddie Stone said it discovered the cross-site scripting (XSS) flaw being abused in the wild as part of a targeted attack. TAG researcher Clément Lecigne has been credited with discovering and reporting the bug.

The disclosure comes as Cisco released patches to remediate a critical flaw in its SD-WAN vManage software (CVE-2023-20214, CVSS score: 9.1) that could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance.

"A successful exploit could allow the attacker to retrieve information from and send information to the configuration of the affected Cisco vManage instance," the company said. "A successful exploit could allow the attacker to retrieve information from and send information to the configuration of the affected Cisco vManage instance."

The vulnerability has been addressed in versions 20.6.3.4, 20.6.4.2, 20.6.5.5, 20.9.3.2, 20.10.1.2, and 20.11.1.2. The networking equipment major said it's not aware of any malicious use of the flaw.

Update

Zimbra on July 26, 2023, released Zimbra Collaboration Suite (ZCS) 10.0.2, ZCS 9.0.0 Patch 34, and ZCS 8.8.15 Patch 41 to address CVE-2023-37580, an actively exploited cross-site scripting vulnerability that it said "could lead to exposure of internal JSP and XML files."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/07/zimbra-warns-of-critical-zero-day-flaw.html