8.8
CVSSv3

CVE-2023-25267

Published: 15/03/2023 Updated: 24/03/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An issue exists in GFI Kerio Connect 9.4.1 patch 1 (fixed in 10.0.0). There is a stack-based Buffer Overflow in the webmail component's 2FASetup function via an authenticated request with a long primaryEMailAddress field to the webmail/api/jsonrpc URI.

Vulnerable Product Search on Vulmon Subscribe to Product

gfi kerio connect 9.4.1