CVE-2025-53645
7.5Zimbra · Collaboration Suite (ZCS)
An unauthenticated remote attacker can cause a denial of service in Zimbra Collaboration Suite by sending crafted GET requests with excessive path segments to the Admin Console.
Executive summary
A vulnerability in the Zimbra Collaboration Suite Admin Console allows an unauthenticated attacker to trigger a denial of service condition through resource exhaustion.
Vulnerability
This vulnerability involves improper handling of excessive, comma-separated path segments within the Admin Console. An unauthenticated remote attacker can exploit this via crafted GET requests to induce uncontrolled resource consumption and service degradation.
Business impact
The exploitation of this flaw leads to a denial of service, which disrupts organizational communication and administrative workflows. Given the CVSS score of 7.5, this high-severity vulnerability poses a significant risk to operational continuity, as the attack vector is network-based and requires no authentication.
Remediation
Immediate Action: Update Zimbra Collaboration Suite to the patched versions: 9.0.0 Patch 46, 10.0.15, or 10.1.9.
Proactive Monitoring: Monitor server resource utilization, specifically CPU and memory spikes, and review web server access logs for anomalous GET requests containing repeated, comma-separated path segments.
Compensating Controls: Deploy a Web Application Firewall (WAF) to filter and block incoming HTTP requests that contain suspicious or malformed path structures directed at the Admin Console.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations should treat this vulnerability with high priority due to the ease of exploitation by unauthenticated actors. Please verify your current ZCS version and apply the vendor-supplied patches immediately to prevent potential service outages.