CVE-2024-5399: Openfind Mail2000 - OS Command Injection
Openfind Mail2000 does not properly filter parameters of specific API. Remote attackers with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the remote server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Openfind Mail2000 V7.0to a version that resolves this vulnerability.Patch Patch 124 - Upgrade
Upgrade
Openfind Mail2000 V8.0to a version that resolves this vulnerability.Patch Patch 31
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5399?
CVE-2024-5399 is classified as a critical severity vulnerability due to its potential to allow remote attackers to execute arbitrary system commands.
How do I fix CVE-2024-5399?
To mitigate CVE-2024-5399, ensure that you update Openfind Mail2000 to the latest patched version provided by the vendor.
Who is affected by CVE-2024-5399?
CVE-2024-5399 affects installations of Openfind Mail2000 that have not properly secured their API parameter filtering.
What type of attacks can be performed using CVE-2024-5399?
CVE-2024-5399 allows attackers with administrative privileges to execute arbitrary system commands on the remote server.
Is it safe to use Openfind Mail2000 with CVE-2024-5399 vulnerability?
Using Openfind Mail2000 with the CVE-2024-5399 vulnerability poses significant security risks and should be addressed immediately.