PT-2023-31552 · Unknown+1 · Zed! For Mac+5

Published

2023-12-13

·

Updated

2023-12-20

·

CVE-2023-50444

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ZED! for Windows versions before Q.2020.3 through Q.2021.2 ZONECENTRAL for Windows versions before Q.2021.2 through 2023.5 ZEDMAIL for Windows versions before 2023.5 ZED! for Windows, Mac, Linux versions before 2023.5
Description The issue concerns .ZED containers produced by PRIMX products, which by default include an encrypted version of sensitive user information. This could allow an unauthenticated attacker to obtain the information via brute force.
Recommendations For ZED! for Windows versions before Q.2020.3 through Q.2021.2, update to a version after Q.2021.2. For ZONECENTRAL for Windows versions before Q.2021.2 through 2023.5, update to a version after 2023.5. For ZEDMAIL for Windows versions before 2023.5, update to a version after 2023.5. For ZED! for Windows, Mac, Linux versions before 2023.5, update to a version after 2023.5.

Fix

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

CVE-2023-50444

Affected Products

Primx
Zed! For Linux
Zed! For Mac
Zed! For Windows
Zedmail For Windows
Zonecentral For Windows