CVE-2023-29046
Connections to external data sources, like e-mail autoconfiguration, were not terminated in case they hit a timeout, instead those connections were logged. Some connections use user-controlled endpoints, which could be malicious and attempt to keep the connection open for an extended period of time. As a result users were able to trigger large amount of egress network connections, possibly exhausting network pool resources and lock up legitimate requests. A new mechanism has been introduced to cancel external connections that might access user-controlled endpoints. No publicly available exploits are known.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.48%
- Percentil entre todas las CVEs puntuadas: 39
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-400
- CWE-400
Referencias
- https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0004.json
- https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6243_7.10.6_2023-08-01.pdf
- https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0004.json
- https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6243_7.10.6_2023-08-01.pdf
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-29046",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@open-xchange.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@open-xchange.com",
"affectedData": [
{
"vendor": "OX Software GmbH",
"modules": [
"backend"
],
"product": "OX App Suite",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "semver",
"lessThanOrEqual": "7.10.6-rev48"
},
{
"status": "affected",
"version": "0",
"versionType": "semver",
"lessThanOrEqual": "8.11"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-11-02T14:15:11.217",
"references": [
{
"url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0004.json",
"source": "security@open-xchange.com"
},
{
"url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6243_7.10.6_2023-08-01.pdf",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "security@open-xchange.com"
},
{
"url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0004.json",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6243_7.10.6_2023-08-01.pdf",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@open-xchange.com",
"description": [
{
"lang": "en",
"value": "CWE-400"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-400"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Connections to external data sources, like e-mail autoconfiguration, were not terminated in case they hit a timeout, instead those connections were logged. Some connections use user-controlled endpoints, which could be malicious and attempt to keep the connection open for an extended period of time. As a result users were able to trigger large amount of egress network connections, possibly exhausting network pool resources and lock up legitimate requests. A new mechanism has been introduced to cancel external connections that might access user-controlled endpoints. No publicly available exploits are known.\n\n"
},
{
"lang": "es",
"value": "Las conexiones a fuentes de datos externas, como la configuración automática de correo electrónico, no finalizaban en caso de que se agotara el tiempo de espera, sino que esas conexiones se registraban. Algunas conexiones utilizan endpoints controlados por el usuario, que podrían ser maliciosos e intentar mantener la conexión abierta durante un período prolongado. Como resultado, los usuarios pudieron activar una gran cantidad de conexiones de red de salida, lo que posiblemente agotó los recursos del grupo de redes y bloqueó solicitudes legítimas. Se ha introducido un nuevo mecanismo para cancelar conexiones externas que podrían acceder a endpoints controlados por el usuario. No se conocen exploits disponibles públicamente."
}
],
"lastModified": "2026-06-17T05:49:14.660",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "59D4F30E-2F52-4948-9C69-C57472833C79",
"versionEndExcluding": "7.10.6"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A144D75D-60A8-4EE0-813C-F658C626B2AA"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6069:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2DA66230-DE02-4881-A893-E9E78286B157"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6073:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "955F3DFB-6479-4867-B62A-82730DBEB498"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6080:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "327D1B56-0D05-4D99-91D4-CC1F0AC32972"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6085:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D0CD0684-C431-47F8-A2F4-1936D5C5A72B"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6093:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EAA6A4A7-C1EE-4716-9F4D-2FF4C4D5FEC8"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6102:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D0968764-CCEE-47A7-9111-E106D887DA43"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6112:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "16589FBB-F0CD-4041-8141-5C89FCCA72AF"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6121:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3CB877EE-A5FE-4FF7-9D21-5C1CFA7343D4"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6133:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0DF5FB90-8D6D-4F99-B454-411B1DFFA630"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6138:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F58876B9-6C2E-4048-A793-B441A84E86F5"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6141:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D5F177CB-CC45-45A0-9D02-C14A13ECC7A3"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6146:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A89A4192-54E9-4899-8C7B-6C7F7E650D5C"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6147:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F2DC1357-9CD5-415F-A190-2F3F4498EF96"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6148:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D78ACF64-2802-44DD-AF7A-1BD5EA7F9908"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6150:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E8F675FA-1684-413A-B1BE-1C5434AC2862"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6156:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F3F1FDC3-35B2-4BDB-A685-75BC72588179"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6161:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5B1E509D-2F41-4296-86D2-6BD71783060F"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6166:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC93EA37-F341-45EC-B651-4F326FB8C613"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6173:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1A4DB8A6-1702-462C-BFCB-39F91D2EFCE1"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6176:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FC0AEFDB-D033-47FC-93FC-8652F922BB8C"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6178:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B5354768-6527-43C2-B492-A8C14AB4E784"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6189:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D83F26D1-B8C6-4114-81EC-810DD5412DC8"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6194:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E9EBC010-9963-4636-96F7-A121FCF755A7"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6199:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F626D64B-C301-4CD8-94B4-48689BD3F29C"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6204:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5E32810C-7B35-42F1-BCA5-E10C02BE2215"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6205:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6539D059-8614-4C26-93C4-C2DDCC5D35E2"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6209:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E359EE75-A2F9-479B-B757-CAE1064AB8F4"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6210:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0BCABDEF-D292-406E-B53C-AFF22484E916"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6214:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ABE8872C-B1DD-4A45-8EF8-E8C355CA6C54"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6215:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "44B20B83-833A-4C68-8693-365BD046C157"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6216:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E254E6D1-D18E-4A2A-A2FF-7D03F39E65DD"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6218:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5F0C5E53-4D15-425A-B4CF-5869353724BF"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6219:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2F4BF5F1-F316-4BAC-83E0-DEAC8C50754E"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6220:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5CDD03A8-5B86-4B87-9C29-6C967261C5C0"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6227:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6071E15F-4D59-41DC-A4D4-7D1AA392A1F2"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6230:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C72C1CEB-7BF7-4A5F-B2E9-397F86CCBF4E"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6233:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5B0F0218-4224-4084-B38D-9719D3782C03"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6235:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BFC41329-1AD6-4575-A22D-977EC5539DA4"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6236:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "217A06B7-0823-4508-BC0C-AD792BA88F7B"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6239:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "246E98B2-A6C8-4410-AA6A-7E81EE8C5E76"
},
{
"criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6241:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "74D1EC02-D009-45DA-B1EC-2219E0F0183C"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@open-xchange.com"
}