PT-2023-31552 · Unknown+1 · Zed! For Mac+5

CVE-2023-50444

·

Publicado

2023-12-13

·

Atualizado

2023-12-20

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ZED! for Windows versions before Q.2020.3 through Q.2021.2 ZONECENTRAL for Windows versions before Q.2021.2 through 2023.5 ZEDMAIL for Windows versions before 2023.5 ZED! for Windows, Mac, Linux versions before 2023.5
Description The issue concerns .ZED containers produced by PRIMX products, which by default include an encrypted version of sensitive user information. This could allow an unauthenticated attacker to obtain the information via brute force.
Recommendations For ZED! for Windows versions before Q.2020.3 through Q.2021.2, update to a version after Q.2021.2. For ZONECENTRAL for Windows versions before Q.2021.2 through 2023.5, update to a version after 2023.5. For ZEDMAIL for Windows versions before 2023.5, update to a version after 2023.5. For ZED! for Windows, Mac, Linux versions before 2023.5, update to a version after 2023.5.

Correção

Improper Restriction of Excessive Authentication Attempts

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-50444

Produtos afetados

Primx
Zed! For Linux
Zed! For Mac
Zed! For Windows
Zedmail For Windows
Zonecentral For Windows