← Back

CVE-2023-50440

nvd nist
Published: Dec 13, 2023Modified: Jun 3, 2025

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before 2023.5; ZEDMAIL for Windows before 2023.5; ZED! for Windows, Mac, Linux before 2023.5; ZEDFREE for Windows, Mac, Linux before 2023.5; or ZEDPRO for Windows, Mac, Linux before 2023.5 can be modified by an unauthenticated attacker to include a UNC reference so that it could trigger network access to an attacker-controlled computer when opened by the victim.

Affected (14)

3 products
Zed!
Zedmail
Zonecentral
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Primx
Before 2023.5
Before 2023.5
Before q.2020.3
From 2023.0 to 2023.5
From q.2021.0 to q.2021.2
Before 2023.5
Before 2023.5
Before 2023.5
Before 2023.5
Before 2023.5
Before 2023.5
Before 2023.5
Primx
Before q.2021.2
From 2023.0 to 2023.5

References (4)

Source: cve@mitre.org
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Product

Timeline

No history available yet.