peter bassill · operator
$ cve CVE-2019-7214 JSON

CVE-2019-7214 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 84.8% (pctl 100)

Patch early

A public exploit exists.

Description

SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely accessible. This port is not accessible remotely by default after applying the Build 6985 patch.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS84.82% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploityes
Published2019-04-24
Last modified2026-06-17

Affected (1)

VendorProduct
smartertoolssmartermail

Public exploits

SourceTitleDate
exploit-dbSmarterMail Build 6985 - Remote Code Execution2020-12-09

References

→ the Explorer  ·  watch your stack  ·  NVD