peter bassill · operator
$ cve CVE-2024-45519 JSON

CVE-2024-45519 KEV

10.0
CRITICAL · CVSS 3.1 · EPSS 99.9% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2024-10-24.

Description

The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS99.91% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-78
On CISA KEVyes — remediate by 2024-10-24
Public exploitnone known
Published2024-10-02
Last modified2026-06-17

CISA KEV

NameSynacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability
Added2024-10-03
Due2024-10-24
Vendor / productSynacor / Zimbra Collaboration Suite (ZCS)
Ransomware usenone reported

Affected (1)

VendorProduct
synacorzimbra collaboration suite

References

→ the Explorer  ·  watch your stack  ·  NVD