PT-2023-20010 · Gfi · Gfi Kerioconnect

·

CVE-2023-25267

·

Published

2023-03-15

·

Updated

2023-03-24

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GFI Kerio Connect versions 9.4.1 patch 1 through 9.4.1 patch 1
Description An issue was discovered in the webmail component's 2FASetup function, which is vulnerable to a stack-based Buffer Overflow. This occurs via an authenticated request with a long primaryEMailAddress field to the "webmail/api/jsonrpc" URI.
Recommendations For GFI Kerio Connect version 9.4.1 patch 1, update to version 10.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the webmail component's 2FASetup function until a patch is available. Avoid using long primaryEMailAddress fields in the affected API endpoint until the issue is resolved.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-25267

Affected Products

Gfi Kerioconnect