← Zuruck zu CVEs
CVE-2019-7214
N/ABeschreibung
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely accessible. This port is not accessible remotely by default after applying the Build 6985 patch.
CVE Details
CVSS v3.1 BewertungN/A
Veroffentlicht4/24/2019
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
smartertools:smartermail
Schwachen (CWE)
CWE-502
Referenzen
http://packetstormsecurity.com/files/160416/SmarterMail-6985-Remote-Code-Execution.html(cve@mitre.org)
http://packetstormsecurity.com/files/173388/SmarterTools-SmarterMail-Remote-Code-Execution.html(cve@mitre.org)
https://www.nccgroup.trust/uk/our-research/technical-advisory-multiple-vulnerabilities-in-smartermail/(cve@mitre.org)
http://packetstormsecurity.com/files/160416/SmarterMail-6985-Remote-Code-Execution.html(af854a3a-2127-422b-91ae-364da2661108)
http://packetstormsecurity.com/files/173388/SmarterTools-SmarterMail-Remote-Code-Execution.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.nccgroup.trust/uk/our-research/technical-advisory-multiple-vulnerabilities-in-smartermail/(af854a3a-2127-422b-91ae-364da2661108)
https://www.smartertools.com/smartermail/release-notes/current(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.