PT-2022-23884 · Mdaemon Technologies · Mdaemon Technologies Securitygateway For Email Servers

Published

2022-08-25

·

Updated

2023-08-08

·

CVE-2022-37240

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MDaemon Technologies SecurityGateway for Email Servers version 8.5.2
Description The issue concerns HTTP Response splitting, which occurs via the format parameter. This allows for potential manipulation of HTTP responses.
Recommendations For MDaemon Technologies SecurityGateway for Email Servers version 8.5.2, consider restricting access to the format parameter to minimize the risk of exploitation until a patch is available. Avoid using the format parameter in affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2022-37240

Affected Products

Mdaemon Technologies Securitygateway For Email Servers