Zertificon · Z1 Securemail Z1 Certserver · CVE-2024-51122
**Name of the Vulnerable Software and Affected Versions**
Zertificon Z1 SecureMail Z1 CertServer version 3.16.4-2516-debian12
**Description**
The issue allows a remote attacker to execute arbitrary code via the `ST`, `L`, `O`, `OU`, `CN` parameters. This enables the attacker to perform unauthorized actions on the affected system.
**Recommendations**
For Zertificon Z1 SecureMail Z1 CertServer version 3.16.4-2516-debian12, consider restricting access to the vulnerable parameters `ST`, `L`, `O`, `OU`, `CN` to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.