HIGH
CVE-2022-27924
CVSS
7.5
KEV
Description
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.
Summary dbcve.org
Zimbra Collaboration 8.8.15 and 9.0 contains an unauthenticated command injection vulnerability in its memcache integration. Attackers can send specially crafted memcache commands that are not properly escaped, allowing arbitrary cached entries to be overwritten.
Mitigation
Apply vendor patches from Zimbra immediately. In the interim, restrict network access to the memcache service and implement proper authentication/segmentation for memcached.
Weakness (CWE)
CWE-74
Injection
EPSS Score
85.4%
Probability of exploitation in next 30 days
99.7th percentile
References
https://wiki.zimbra.com/wiki/Security_Center
Vendor Advisory
https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P24
Release Notes, Vendor Advisory
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-27924
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.