SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-7214

SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data.

CRITICAL 9.8EPSS 84.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 84.8%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely accessible. This port is not accessible remotely by default after applying the Build 6985 patch.

CVSS 3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
84.82% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-502
Affected
smartertools/smartermail
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.