go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Openfind Mail2000 - OS Command Injection

TVN ID TVN-202405003
CVE ID CVE-2024-5399
CVSS 7.2 (High)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Products Mail2000 V7.0 from Patch 55 before Patch 124
Mail2000 V8.0 before Patch 31
Description Openfind Mail2000 does not properly filter parameters of specific API. Remote attackers with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the remote server.
Solution Update Mail2000 V7.0 to Patch 124 or later version.
Update Mail2000 V8.0 to Patch 31 or later version
Credit Openfind tech team(Openfind Information Technology, Inc.)
Public Date 2024-05-27
Top