Source: Ministry of education information & communication security contingency platform
| Publication Number | TACERT-ANA-2024080110080606 | Publication Time | 2024/08/01 10:03 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2024/07/31 10:03 |
| Impact Level | Medium | ||
| [Subject] 【Vulnerability Alert】 Critical OS Command Injection Vulnerability in Softnext Mail SQR Expert and Mail Archiving Expert, Immediate Remediation Required |
|||
| [Content] Forwarded from TWCERTCC-200-202407-00000001 TWCERT/CC announced TVN-202407011 on 20240729, detailing a critical OS command injection vulnerability (CVE-2024-5670, CVSS:9.8) in Softnext Mail SQR Expert and Mail Archiving Expert. This vulnerability is due to improper validation of user inputs in the web service, allowing unauthenticated remote attackers to inject and execute arbitrary OS commands on the remote server. Information Sharing Level: WHITE (Information content can be publicly disclosed) |
|||
| [Affected Platform] ●Softnext Mail SQR Expert ●Softnext Mail Archiving Expert |
|||
| [Recommended Actions] 1. Affected Products ●SN OS 12.1 versions prior to and including 230921 ●SN OS 12.3 versions prior to and including 230921 ●SN OS 10.3 versions prior to and including 230630 2. Solution ●Update SN OS 12.1 to version 230922 or later ●Update SN OS 12.3 to version 230922 or later ●Update SN OS 10.3 to version 230631 or later Products running on FreeBSD 9.x will not support updates; please update the operating system version first. |
|||
| [Reference] 1. https://www.twcert.org.tw/tw/cp-132-7958-817f4-1.html |
|||