Critical Zimbra Flaw Lets Attackers Inject Commands Through the SNMP Monitoring Service
ID: 17d5732c-c931-57b3-a251-c6d945bc058a
STIX ID: report--17d5732c-c931-57b3-a251-c6d945bc058a
Feed Name: cybersecurityNews.com
Threat Score
Zimbra released version 10.1.20 to address a critical SNMP-based command injection vulnerability in the Zimbra Collaboration Suite that can allow remote attackers to execute arbitrary commands via malicious SNMP notifications; the update also fixes multiple XSS, an SSRF in Nextcloud integration, authorization issues, and a mail-forwarding bypass, and administrators are urged to upgrade, harden SNMP configurations, and monitor for suspicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
