The web services of Softnext's products, Mail SQR Expert and Mail Archiving Expert do not properly validate user input, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the remote server.
Metrics
Affected Vendors & Products
Fixes
Solution
Update SN OS 12.1 to version 230922 or later Update SN OS 12.3 to version 230922 or later Update SN OS 10.3 to version 230631 or later For affected products running on FreeBSD 9.x, updates will not be supported. Please upgrade the operating system version first.
Workaround
No workaround given by the vendor.
References
History
Fri, 13 Sep 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Softnext
Softnext sn Os |
|
CPEs | cpe:2.3:o:softnext:sn_os:10.3:-:*:*:*:*:*:* cpe:2.3:o:softnext:sn_os:12.1:-:*:*:*:*:*:* cpe:2.3:o:softnext:sn_os:12.3:-:*:*:*:*:*:* |
|
Vendors & Products |
Softnext
Softnext sn Os |

Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-08-01T21:18:06.849Z
Reserved: 2024-06-06T02:51:23.493Z
Link: CVE-2024-5670

Updated: 2024-08-01T21:18:06.849Z

Status : Modified
Published: 2024-07-29T03:15:02.167
Modified: 2024-11-21T09:48:07.687
Link: CVE-2024-5670

No data.

No data.