Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9533-x7q2-r9j9

Опубликовано: 12 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Zimbra Collaboration Open Source 8.8.15 does not encrypt the initial-login randomly created password (from the "zmprove ca" command). It is visible in cleartext on port UDP 514 (aka the syslog port).

Zimbra Collaboration Open Source 8.8.15 does not encrypt the initial-login randomly created password (from the "zmprove ca" command). It is visible in cleartext on port UDP 514 (aka the syslog port).

EPSS

Процентиль: 84%
0.02171
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

Zimbra Collaboration Open Source 8.8.15 does not encrypt the initial-login randomly created password (from the "zmprove ca" command). It is visible in cleartext on port UDP 514 (aka the syslog port). NOTE: a third party reports that this cannot be reproduced.

EPSS

Процентиль: 84%
0.02171
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-863