Insecure Initial Password Handling in Zimbra Collaboration Open Source by Zimbra
CVE-2022-32294

9.8CRITICAL

Key Information:

Vendor

Zimbra

Vendor
CVE Published:
11 July 2022

What is CVE-2022-32294?

The Zimbra Collaboration Open Source version 8.8.15 fails to properly encrypt the randomly generated initial-login password created by the 'zmprove ca' command. Instead, this sensitive password is transmitted in cleartext over UDP port 514, which is typically used for syslog communications, posing a significant security risk. While some reports indicate that this issue may not be reproducible, it raises concerns about password exposure and overall security in the transmission of sensitive data.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-32294 : Insecure Initial Password Handling in Zimbra Collaboration Open Source by Zimbra