CVE-2022-27924

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance....

Basic Information

CVE State
PUBLISHED
Reserved Date
March 25, 2022
Published Date
April 20, 2022
Last Updated
January 29, 2025
Vendor
n/a
Product
n/a
Description
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.

CVSS Scores

CVSS v3.1

7.5 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
partial

Exploit Status

Exploited in the Wild
Yes (added 2022-08-04 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2022-08-04 00:00:00 UTC