PT-2025-6704 · Zertificon · Z1 Securemail Z1 Certserver

Marc Mahlke

·

Published

2025-02-12

·

Updated

2025-02-13

·

CVE-2024-51122

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Zertificon Z1 SecureMail Z1 CertServer version 3.16.4-2516-debian12
Description The issue allows a remote attacker to execute arbitrary code via the ST, L, O, OU, CN parameters. This enables the attacker to perform unauthorized actions on the affected system.
Recommendations For Zertificon Z1 SecureMail Z1 CertServer version 3.16.4-2516-debian12, consider restricting access to the vulnerable parameters ST, L, O, OU, CN to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-51122

Affected Products

Z1 Securemail Z1 Certserver