CVE-2024-45519

Published Oct 2, 2024

Last updated 25 days ago

Overview

Description
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.
Source
cve@mitre.org
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Synacor Zimbra Collaboration Command Execution Vulnerability
Exploit added on
Oct 3, 2024
Exploit action due
Oct 24, 2024
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weaknesses

nvd@nist.gov
NVD-CWE-Other
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-284

Social media

Hype score
Not currently trending
  1. Zimbra - Remote Command Execution (CVE-2024-45519) https://t.co/TOaWX6NRxw #Pentesting #CyberSecurity #Infosec https://t.co/QuIGRuHjyO

    @ptracesecurity

    11 Nov 2024

    1353 Impressions

    7 Retweets

    20 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  2. MasterCLASS - Mitigando la vulnerabilidad CVE-2024-45519 en Zimbra - YouTube https://t.co/RuOEkCjfL0

    @escudata

    10 Nov 2024

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. ''Zimbra - Remote Command Execution (CVE-2024-45519)'' #infosec #pentest #redteam #blueteam https://t.co/4dtaFjOx33

    @CyberWarship

    10 Nov 2024

    5337 Impressions

    38 Retweets

    85 Likes

    37 Bookmarks

    0 Replies

    1 Quote

  4. ¿Utilizas #Zimbra? Deberías leer esto! Remote Command Execution (CVE-2024-45519 - CVSS 9.8) Versiones: 8.8.15 - 10.1.0 https://t.co/EWq876GY16 https://t.co/M2AAEf2jmy ¿Por qué? Porque hay un exploit y un template de Nuclei: https://t.co/QlKprtrFsr

    @SeguInfo

    7 Nov 2024

    4876 Impressions

    27 Retweets

    65 Likes

    33 Bookmarks

    3 Replies

    0 Quotes

  5. 🚨CVE-2024-45519 - Zimbra Postjournal Exploit Setup https://t.co/8lEu4C9kJn

    @DarkWebInformer

    5 Nov 2024

    4152 Impressions

    7 Retweets

    22 Likes

    7 Bookmarks

    0 Replies

    0 Quotes

  6. Actively exploited CVE : CVE-2024-45519

    @transilienceai

    4 Nov 2024

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. Actively exploited CVE : CVE-2024-45519

    @transilienceai

    30 Oct 2024

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  8. Zimbra - Remote Command Execution (CVE-2024-45519) #Zimbra #RemoteCommandExecution #CVE202445519 #Nuclei #BugBounty https://t.co/EdrirR527d

    @reverseame

    30 Oct 2024

    2172 Impressions

    16 Retweets

    28 Likes

    8 Bookmarks

    0 Replies

    0 Quotes

  9. Actively exploited CVE : CVE-2024-45519

    @transilienceai

    29 Oct 2024

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  10. Actively exploited CVE : CVE-2024-45519

    @transilienceai

    25 Oct 2024

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  11. Actively exploited CVE : CVE-2024-45519

    @transilienceai

    23 Oct 2024

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  12. GitHub - Chocapikk/CVE-2024-45519: Zimbra - Remote Command Execution (CVE-2024-45519) https://t.co/6KZ9WQ2ePK

    @akaclandestine

    20 Oct 2024

    1392 Impressions

    2 Retweets

    14 Likes

    8 Bookmarks

    0 Replies

    0 Quotes

  13. Actively exploited CVE : CVE-2024-45519

    @transilienceai

    20 Oct 2024

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  14. Actively exploited CVE : CVE-2024-45519

    @transilienceai

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  15. Actively exploited CVE : CVE-2024-45519

    @transilienceai

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations