← back
CVE-2019-7214

CVE-2019-7214

60Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 85%
from disclosure to weapon595 days
Published on NVDApr 24
1st PoC+595d
metasploitApr 17
exploitation probability
85%top 1% of all CVEs
observed exploitation
nono source reports it
7 public exploit(s)
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely accessible. This port is not accessible remotely by default after applying the Build 6985 patch.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.