10
CVE-2019-7214
- EPSS 82.93%
- Veröffentlicht 24.04.2019 15:29:02
- Zuletzt bearbeitet 21.11.2024 04:47:45
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely accessible. This port is not accessible remotely by default after applying the Build 6985 patch.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SmarterTools ≫ SmarterMail Version >= 16.0.6345 < 16.3.6985
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 82.93% | 0.992 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.