7.5
CVSSv2

CVE-2022-26562

Published: 01/04/2022 Updated: 11/05/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue in provider/libserver/ECKrbAuth.cpp of Kopano Core <= v11.0.2.51 contains an issue which allows malicious users to authenticate even if the user account or password is expired. It also exists in the predecessor Zarafa Collaboration Platform (ZCP) in provider/libserver/ECPamAuth.cpp of Zarafa >= 6.30 (introduced between 6.30.0 RC1e and 6.30.8 final).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kopano groupware core 11.0.2.51

Vendor Advisories

Debian Bug report logs - #1016973 kopanocore: CVE-2022-26562 Package: src:kopanocore; Maintainer for src:kopanocore is Giraffe Maintainers &lt;pkg-giraffe-maintainers@alioth-listsdebiannet&gt;; Reported by: Moritz Mühlenhoff &lt;jmm@inutilorg&gt; Date: Wed, 10 Aug 2022 20:09:02 UTC Severity: important Tags: security, upstrea ...