CVE-2024-52875 is a critical vulnerability affecting GFI Kerio Control versions 9.2.5 through 9.4.5. It stems from improper sanitization of the 'dest' GET parameter, leading to Open Redirect, HTTP Response Splitting, and ultimately Reflected Cross-Site Scripting (XSS). This flaw can be leveraged for remote command execution through the admin interface's upgrade feature. With a CVSS score of 8.8 (HIGH) and an EPSS percentile of 99.02%, the vulnerability is easily exploitable over the network with low attack complexity, potentially leading to high impact on confidentiality, integrity, and availability. Active exploitation has been confirmed, with multiple media outlets reporting on over 12,000 Kerio Control firewalls exposed to RCE attacks and hackers stealing admin CSRF tokens. While no Metasploit or ExploitDB modules exist, Nuclei templates for CRLF injection are available, and there is significant community discussion and media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.2.5, <= 9.4.5CPE matchmatch criteria | cpe:2.3:a:gfi:kerio_control:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.