go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Openfind MailGates and MailAudit - OS Command Injection

TVN ID TVN-202406016
CVE ID CVE-2024-6048
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products MailGates 5.0/6.0、MailAudit 5.0/6.0
Description Openfind's MailGates and MailAudit fail to properly filter user input when analyzing email attachments. An unauthenticated remote attacker can exploit this vulnerability to inject system commands and execute them on the remote server.
Solution Update MailGates/MailAudit v5.0 to Patch 5.2.10.094 or later.
Update MailAudit/MailAudit v6.0 to Patch 6.1.7.037 or later.
Credit Openfind tech team(Openfind Information Technology, Inc.)
Public Date 2024-06-17
Top