{"id":63825,"date":"2023-10-11T11:30:05","date_gmt":"2023-10-11T16:30:05","guid":{"rendered":"https:\/\/blog.cpanel.com\/?p=63825"},"modified":"2023-10-11T11:30:05","modified_gmt":"2023-10-11T16:30:05","slug":"cpanel-vulnerability-report-no-actions-required-by-default","status":"publish","type":"post","link":"https:\/\/devel.www.cpanel.net\/blog\/products\/cpanel-vulnerability-report-no-actions-required-by-default\/","title":{"rendered":"cPanel Vulnerability Report: No Actions Required by Default"},"content":{"rendered":"\n
Just a few days ago, Zero Day Initiative (ZDI) publicly disclosed not one, not two, but six Zero-Day vulnerabilities in the widely-used Exim mail server. These vulnerabilities have been lurking in the shadows since their discovery in June 2022, when precautionary steps were taken to release patches for Exim and libspf2. Now, the vulnerabilities are finally unraveled. And spoiler alert, you are totally safe!<\/p>\n\n\n\n
At cPanel, we prioritize the security of your hosting environments. Therefore, we provide you with important information regarding the recent Zero-Day vulnerabilities that have been disclosed for Exim, the message transfer agent (MTA) used on millions of systems worldwide.<\/p>\n\n\n\n
Based on our latest risk assessment and understanding of the defect reports, no further action is required from your side<\/strong>. Further changes in cPanel & WHM of any version are not needed.<\/p>\n\n\n\n Exim serves as a robust message transfer agent (MTA) initially created at the University of Cambridge for Unix systems that maintain internet connectivity. This versatile MTA boasts a widespread presence across millions of systems globally and has a track record of encountering noteworthy security challenges.<\/p>\n\n\n\n Here is what we currently know about the Zero-Day vulnerabilities recently disclosed through the Zero Day Initiative (ZDI):<\/p>\n\n\n\n CVE-2023-42115<\/strong><\/a>:<\/strong> CVE-2023-42114<\/strong><\/a> <\/strong>& <\/strong>CVE-2023-42116<\/strong><\/a>:<\/strong> CVE-2023-42117<\/strong><\/a>:<\/strong>What is Exim?<\/strong><\/h2>\n\n\n\n
Risk Assessment: Understanding the Zero-Day Disclosures<\/strong><\/h2>\n\n\n\n
Exim addressed issues specific to external authentication. If you are using cPanel Exim with the default settings, you are not vulnerable<\/strong> to this issue unless the ‘external’ authentication driver is explicitly enabled.<\/p>\n\n\n\n
Exim fixed vulnerabilities related to SPA (Secure Password Authentication) and NTLM (NT LAN Manager). By default, cPanel Exim is not vulnerable to these issues unless the ‘SPA’ authentication driver is activated.<\/strong><\/p>\n\n\n\n
There is a known defect related to proxy protocol usage in Exim. This only poses a risk if your mail traffic is being proxied to your server<\/strong>, and the proxy is untrusted. We recommend verifying the trustworthiness of your proxy.<\/p>\n\n\n\n