PT-2023-20010 · Gfi · Gfi Kerioconnect
Frycos
·
Published
2023-03-15
·
Updated
2023-03-24
·
CVE-2023-25267
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GFI Kerio Connect versions 9.4.1 patch 1 through 9.4.1 patch 1
Description
An issue was discovered in the webmail component's 2FASetup function, which is vulnerable to a stack-based Buffer Overflow. This occurs via an authenticated request with a long
primaryEMailAddress field to the "webmail/api/jsonrpc" URI.Recommendations
For GFI Kerio Connect version 9.4.1 patch 1, update to version 10.0.0 to resolve the issue.
As a temporary workaround, consider restricting access to the webmail component's 2FASetup function until a patch is available.
Avoid using long
primaryEMailAddress fields in the affected API endpoint until the issue is resolved.Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gfi Kerioconnect