CVE-2024-5400: Openfind Mail2000 - OS Command Injection
Openfind Mail2000 does not properly filter parameters of specific CGI. Remote attackers with regular privileges can exploit this vulnerability to execute arbitrary system commands on the remote server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Openfind Mail2000 V8.0to a version that resolves this vulnerability.Patch Patch 34
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5400?
CVE-2024-5400 is classified as a critical vulnerability due to its potential for arbitrary command execution.
How do I fix CVE-2024-5400?
To mitigate CVE-2024-5400, ensure you apply the latest security patches from Openfind for Mail2000.
Who is affected by CVE-2024-5400?
CVE-2024-5400 affects users of Openfind Mail2000 who are running outdated versions of the software.
What type of attacks can be carried out using CVE-2024-5400?
Attackers can exploit CVE-2024-5400 to execute arbitrary system commands on a vulnerable server.
Is authentication required to exploit CVE-2024-5400?
No, attackers can exploit CVE-2024-5400 with regular privileges, making it accessible without authentication.