CVE-2018-6289
9.8
CRITICAL · CVSS 3.0 · EPSS 6.6% (pctl 94)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.6% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-74 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-02-06 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| kaspersky | secure mail gateway |
References
- https://support.kaspersky.com/vulnerability.aspx?el=12430#010218
- https://www.coresecurity.com/advisories/kaspersky-secure-mail-gateway-multiple-vulnerabilities
- https://support.kaspersky.com/vulnerability.aspx?el=12430#010218
- https://www.coresecurity.com/advisories/kaspersky-secure-mail-gateway-multiple-vulnerabilities
→ the Explorer · watch your stack · NVD