Analyse sur rafaelpfister.ch

Description de l'éditeur (en anglais)

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Données de référence

Éditeur
Zimbra
Produits concernés
  • Collaboration
CVSS 3.1
8.9 (HIGH)
Vecteur
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Type de faiblesse
CWE-78: OS Command Injection
Publiée
13 août 2026
Dans le catalogue KEV depuis
21 août 2026
Échéance administrations fédérales US
24 août 2026

Sources officielles

← Toutes les vulnérabilités