CVE-2019-7214
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 85%
from disclosure to weapon595 days
Published on NVDApr 24
1st PoC+595d
metasploitApr 17
exploitation probability
85%top 1% of all CVEs
observed exploitation
nono source reports it
7 public exploit(s)
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely accessible. This port is not accessible remotely by default after applying the Build 6985 patch.
Affected products
n/a · n/apublic PoCs found — 7
exploitdbwww.exploit-db.com/exploits/49216unverifiedgithubgithub.com/Drew-Alleman/CVE-2019-7214★ 4githubgithub.com/devzspy/CVE-2019-7214★ 2githubgithub.com/andyfeili/-CVE-2019-7214★ 1githubgithub.com/ElusiveHacker/CVE-2019-7214★ 0cve_referencepacketstormsecurity.com/files/160416/SmarterMail-6985-Remote-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/173388/SmarterTools-SmarterMail-Remote-Code-Execution.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/160416/SmarterMail-6985-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/173388/SmarterTools-SmarterMail-Remote-Code-Execution.htmlhttps://www.nccgroup.trust/uk/our-research/technical-advisory-multiple-vulnerabilities-in-smartermail/https://www.smartertools.com/smartermail/release-notes/current