Impact
The flaw is a command‑injection weakness that allows an unauthenticated attacker to send crafted SMTP requests through SNMP notifications, causing the Zimbra server to execute arbitrary operating‑system commands as the Zimbra user. This can give the attacker full control of the affected system. The underlying weakness is command injection (CWE‑78).
Affected Systems
Zimbra Collaboration (ZCS) versions earlier than 10.1.20 are impacted, but only when the optional zimbra‑snmp package is installed and SNMP notifications are enabled. The vulnerability exists in the notification processing code that handles untrusted SNMP input.
Risk and Exploitability
The CVSS score of 8.9 indicates a high severity. No EPSS score is reported, and the vulnerability is not currently listed in the CISA KEV catalog, but the lack of authentication and remote access via SNMP mean that the attack can be launched from a network accessible to the attacker. The combination of high severity, a remote attack vector, and the ability to execute arbitrary code makes the risk significant and warrants urgent action.
OpenCVE Enrichment