PT-2024-10233 · Cellopoint · Cellopoint Secure Email Gateway
Published
2024-09-20
·
Updated
2024-10-03
·
CVE-2024-9043
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cellopoint Secure Email Gateway versions prior to 4.5.0
Description
The issue is related to a Buffer Overflow Vulnerability in the authentication process of the Secure Email Gateway from Cellopoint. Remote unauthenticated attackers can send crafted packets to crash the process, thereby bypassing authentication and obtaining system administrator privileges. This vulnerability may allow an attacker to elevate their privileges or cause a denial of service.
Recommendations
For Cellopoint Secure Email Gateway versions prior to 4.5.0, patch immediately to prevent remote exploitation. As a temporary workaround, consider restricting access to the authentication process until a patch is available. Avoid using the vulnerable authentication component until the issue is resolved. At the moment, there is no additional information about other mitigation measures.
Exploit
Fix
Memory Corruption
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cellopoint Secure Email Gateway