🔙 목록으로 돌아가기

CVE-2022-27924: Zimbra Collaboration Suite - Memcached Command Injection

TitleZimbra Collaboration Suite - Memcached Command Injection
Authorrxerium
SeverityHigh
ImpactSuccessful exploitation allows attackers to overwrite arbitrary cached entries and steal user credentials in cleartext without user interaction. With valid credentials, attackers can perform spear phishing, social engineering, and business email compromise attacks, or maintain persistent access via webshells.
RemediationUpdate to Zimbra Collaboration Suite version 8.8.15 Patch 31 or 9.0.0 Patch 24.1 or later. Implement multi-factor authentication to mitigate credential theft impact.
CVSS Score9.8
EPSS Score0.91955
CVE IDCVE-2022-27924
Shodan Queryhttp.title:"zimbra collaboration suite"
Tags cve cve2022 zimbra injection passive vuln kev vkev

🔍 Vulnerability Description

Zimbra Collaboration Suite versions 8.8.15 and 9.0 contain a memcached command injection vulnerability that allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance, leading to cache poisoning and potential credential theft.

🌐 HTTP Request

GET /js/zimbraMail/share/model/ZmSettings.js HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Mac OS X 13_2) AppleWebKit/537.36 (KHTML, like Gecko) Edge/117.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-27924.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-27924.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A