CVE-2019-7214
critical · 9.8SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely accessible. This port is not accessible remotely by default after applying the Build 6985 patch.
9.8
CVSS
84.8%
EPSS (exploit prob.)
100th
EPSS percentile
2019-04-24
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-502
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| smartertools | smartermail | >= 16.0.6345, < 16.3.6985 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/160416/SmarterMail-6985-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/173388/SmarterTools-SmarterMail-Remote-Code-Execution.html
- https://www.nccgroup.trust/uk/our-research/technical-advisory-multiple-vulnerabilities-in-smartermail/
- https://www.smartertools.com/smartermail/release-notes/current
- http://packetstormsecurity.com/files/160416/SmarterMail-6985-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/173388/SmarterTools-SmarterMail-Remote-Code-Execution.html
- https://www.nccgroup.trust/uk/our-research/technical-advisory-multiple-vulnerabilities-in-smartermail/
- https://www.smartertools.com/smartermail/release-notes/current
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-7214