Vulnerabilities
Vulnerable Software
Gfi:  >> Kerio Connect  Security Vulnerabilities
An issue was discovered in GFI Kerio Connect 9.4.1 patch 1 (fixed in 10.0.0). There is a stack-based Buffer Overflow in the webmail component's 2FASetup function via an authenticated request with a long primaryEMailAddress field to the webmail/api/jsonrpc URI.
CVSS Score
8.8
EPSS Score
0.001
Published
2023-03-15
Kerio Connect 8.0.0 through 9.2.2, and Kerio Connect Client desktop application for Windows and Mac 9.2.0 through 9.2.2, when e-mail preview is enabled, allows remote attackers to conduct clickjacking attacks via a crafted e-mail message.
CVSS Score
6.5
EPSS Score
0.002
Published
2017-05-02


Contact Us

Shodan ® - All rights reserved