PT-2022-23886 · Mdaemon Technologies · Mdaemon Technologies Securitygateway For Email Servers

Published

2022-08-25

·

Updated

2023-08-08

·

CVE-2022-37242

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MDaemon Technologies SecurityGateway for Email Servers version 8.5.2
Description The issue concerns HTTP Response splitting, which occurs via the data parameter. This allows for potential manipulation of HTTP responses.
Recommendations For version 8.5.2, avoid using the data parameter in affected API endpoints until the issue is resolved. Consider restricting access to the vulnerable component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2022-37242

Affected Products

Mdaemon Technologies Securitygateway For Email Servers