CVE-2022-39052: DoS attack using email
Published Oct 17, 2022
·Updated
An external attacker is able to send a specially crafted email (with many recipients) and trigger a potential DoS of the system
Affected Software
3 affected components
OTRS OTRS>=6.0.0<=6.0.32
OTRS OTRS>=7.0.0<7.0.39
OTRS OTRS>=8.0.0<8.0.26
Remediation
Information
Update to OTRS 8.0.26 or OTRS 7.0.38.
Event History
Oct 17, 2022
CVE Published
via MITRE·08:55 AM
Data Sourced
via MITRE·08:55 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-39052.
2
What is the severity of CVE-2022-39052?
The severity of CVE-2022-39052 is high with a score of 6.5.
3
How does the vulnerability CVE-2022-39052 impact the system?
The vulnerability allows an external attacker to send a specially crafted email with many recipients and trigger a potential DoS (Denial of Service) of the system.
4
Which software versions are affected by CVE-2022-39052?
The software versions affected by CVE-2022-39052 are OTRS 6.0.0 to 6.0.32, OTRS 7.0.0 to 7.0.39, and OTRS 8.0.0 to 8.0.26.
5
How can I fix the vulnerability CVE-2022-39052?
To fix the vulnerability CVE-2022-39052, update your OTRS software to a version that is not affected by the vulnerability. Refer to the OTRS Security Advisory (link provided) for more information.