VulnerabilityModified
CVE-2019-7214
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data.
CRITICAL 9.8EPSS 84.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 84.8%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely accessible. This port is not accessible remotely by default after applying the Build 6985 patch.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 84.82% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- smartertools/smartermail
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/160416/SmarterMail-6985-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/173388/SmarterTools-SmarterMail-Remote-Code-Execution.html
- https://www.nccgroup.trust/uk/our-research/technical-advisory-multiple-vulnerabilities-in-smartermail/Third Party Advisory
- https://www.smartertools.com/smartermail/release-notes/currentExploit, Release Notes, Vendor Advisory
- http://packetstormsecurity.com/files/160416/SmarterMail-6985-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/173388/SmarterTools-SmarterMail-Remote-Code-Execution.html
- https://www.nccgroup.trust/uk/our-research/technical-advisory-multiple-vulnerabilities-in-smartermail/Third Party Advisory
- https://www.smartertools.com/smartermail/release-notes/currentExploit, Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.