Lucene search

K
nvd[email protected]NVD:CVE-2023-50444
HistoryDec 13, 2023 - 8:15 p.m.

CVE-2023-50444

2023-12-1320:15:49
CWE-307
web.nvd.nist.gov
4
primx zed! containers
zedmail
unencrypted sensitive information
unauthenticated access
brute force

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

39.8%

By default, .ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before 2023.5; ZEDMAIL for Windows before 2023.5; and ZED! for Windows, Mac, Linux before 2023.5 include an encrypted version of sensitive user information, which could allow an unauthenticated attacker to obtain it via brute force.

Affected configurations

Nvd
Node
primxzed\!Range<q.2020.3enterprisewindows
OR
primxzed\!Range2023.02023.5enterprisewindows
OR
primxzed\!Rangeq.2021.0q.2021.2enterprisewindows
OR
primxzedmailRange<2023.5windows
OR
primxzonecentralRange<q.2021.2windows
OR
primxzonecentralRange2023.02023.5windows
VendorProductVersionCPE
primxzed\!*cpe:2.3:a:primx:zed\!:*:*:*:*:enterprise:windows:*:*
primxzedmail*cpe:2.3:a:primx:zedmail:*:*:*:*:*:windows:*:*
primxzonecentral*cpe:2.3:a:primx:zonecentral:*:*:*:*:*:windows:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

39.8%

Related for NVD:CVE-2023-50444