CVE-2024-45519

Published Oct 2, 2024

Last updated a day ago

Overview

Description
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.
Source
cve@mitre.org
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability
Exploit added on
Oct 3, 2024
Exploit action due
Oct 24, 2024
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-78

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

1

  1. Explore Cool CVEs 🔹 CVE-2024-45519 🔹 CVE-2024-46538 🔹 CVE-2024-49113 🔹 CVE-2024-9264 🔹 CVE-2025-0411 🔹 CVE-2020-7660 Check it out & level up your exploit game! https://t.co/ZNLzGRXrDy #CyberSecurity #ExploitDev #RedTeam

    @defhawk_specter

    23 Feb 2025

    83 Impressions

    1 Retweet

    4 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  2. Zimbra - Remote Command Execution (CVE-2024-45519) https://t.co/J7al6SPWDd https://t.co/dB58O7HiRU

    @TareqALhazzaa

    23 Dec 2024

    1087 Impressions

    4 Retweets

    24 Likes

    6 Bookmarks

    0 Replies

    0 Quotes

  3. ⚫️CVE-2024-6387 : OpenSSH 'user authenticatio' 8.5p1 – 9.7p1 -Input validation 2 Remote Code Execution (regreSSHion) POC : https://t.co/72BHyG0iqJ ⚫️CVE-2024-45519 : Zimbra Collaboration Suite 'postjournal' $versions - Remote Code Execution POC : https://t.co/Wb18o30BII

    @HackingTeam777

    21 Dec 2024

    737 Impressions

    2 Retweets

    23 Likes

    7 Bookmarks

    1 Reply

    0 Quotes

  4. Feeling untouchable in #CyberSecurity? Zimbra Collaboration's got a nasty surprise for you. CVE-2024-45519, a perfect 10 on the CVSS, is out and about wreaking havoc. Stay ahead or become a statistic. A patch in your armour? @securityaffairs #infosec #ZimbraVulnerability https://

    @LimitedViewX

    5 Dec 2024

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Zimbra - Remote Command Execution (CVE-2024-45519) https://t.co/TOaWX6NRxw #Pentesting #CyberSecurity #Infosec https://t.co/QuIGRuHjyO

    @ptracesecurity

    11 Nov 2024

    1353 Impressions

    7 Retweets

    20 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  6. MasterCLASS - Mitigando la vulnerabilidad CVE-2024-45519 en Zimbra - YouTube https://t.co/RuOEkCjfL0

    @escudata

    10 Nov 2024

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. ''Zimbra - Remote Command Execution (CVE-2024-45519)'' #infosec #pentest #redteam #blueteam https://t.co/4dtaFjOx33

    @CyberWarship

    10 Nov 2024

    5337 Impressions

    38 Retweets

    85 Likes

    37 Bookmarks

    0 Replies

    1 Quote

  8. ¿Utilizas #Zimbra? Deberías leer esto! Remote Command Execution (CVE-2024-45519 - CVSS 9.8) Versiones: 8.8.15 - 10.1.0 https://t.co/EWq876GY16 https://t.co/M2AAEf2jmy ¿Por qué? Porque hay un exploit y un template de Nuclei: https://t.co/QlKprtrFsr

    @SeguInfo

    7 Nov 2024

    4876 Impressions

    27 Retweets

    65 Likes

    33 Bookmarks

    3 Replies

    0 Quotes

  9. 🚨CVE-2024-45519 - Zimbra Postjournal Exploit Setup https://t.co/8lEu4C9kJn

    @DarkWebInformer

    5 Nov 2024

    4152 Impressions

    7 Retweets

    22 Likes

    7 Bookmarks

    0 Replies

    0 Quotes

  10. Actively exploited CVE : CVE-2024-45519

    @transilienceai

    4 Nov 2024

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  11. Actively exploited CVE : CVE-2024-45519

    @transilienceai

    30 Oct 2024

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  12. Zimbra - Remote Command Execution (CVE-2024-45519) #Zimbra #RemoteCommandExecution #CVE202445519 #Nuclei #BugBounty https://t.co/EdrirR527d

    @reverseame

    30 Oct 2024

    2172 Impressions

    16 Retweets

    28 Likes

    8 Bookmarks

    0 Replies

    0 Quotes

  13. Actively exploited CVE : CVE-2024-45519

    @transilienceai

    29 Oct 2024

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  14. Actively exploited CVE : CVE-2024-45519

    @transilienceai

    25 Oct 2024

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  15. Actively exploited CVE : CVE-2024-45519

    @transilienceai

    23 Oct 2024

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  16. GitHub - Chocapikk/CVE-2024-45519: Zimbra - Remote Command Execution (CVE-2024-45519) https://t.co/6KZ9WQ2ePK

    @akaclandestine

    20 Oct 2024

    1392 Impressions

    2 Retweets

    14 Likes

    8 Bookmarks

    0 Replies

    0 Quotes

  17. Actively exploited CVE : CVE-2024-45519

    @transilienceai

    20 Oct 2024

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  18. Actively exploited CVE : CVE-2024-45519

    @transilienceai

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  19. Actively exploited CVE : CVE-2024-45519

    @transilienceai

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations