CVE-2025-53645

7.5

Zimbra · Collaboration Suite (ZCS)

An unauthenticated remote attacker can cause a denial of service in Zimbra Collaboration Suite by sending crafted GET requests with excessive path segments to the Admin Console.

Executive summary

A vulnerability in the Zimbra Collaboration Suite Admin Console allows an unauthenticated attacker to trigger a denial of service condition through resource exhaustion.

Vulnerability

This vulnerability involves improper handling of excessive, comma-separated path segments within the Admin Console. An unauthenticated remote attacker can exploit this via crafted GET requests to induce uncontrolled resource consumption and service degradation.

Business impact

The exploitation of this flaw leads to a denial of service, which disrupts organizational communication and administrative workflows. Given the CVSS score of 7.5, this high-severity vulnerability poses a significant risk to operational continuity, as the attack vector is network-based and requires no authentication.

Remediation

Immediate Action: Update Zimbra Collaboration Suite to the patched versions: 9.0.0 Patch 46, 10.0.15, or 10.1.9.

Proactive Monitoring: Monitor server resource utilization, specifically CPU and memory spikes, and review web server access logs for anomalous GET requests containing repeated, comma-separated path segments.

Compensating Controls: Deploy a Web Application Firewall (WAF) to filter and block incoming HTTP requests that contain suspicious or malformed path structures directed at the Admin Console.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations should treat this vulnerability with high priority due to the ease of exploitation by unauthenticated actors. Please verify your current ZCS version and apply the vendor-supplied patches immediately to prevent potential service outages.

More Zimbra CVEs

Sources