CVE-2019-7214

SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely accessible. This port is not accessible remotely by default after applying the Build 6985 patch.
Configurations

Configuration 1 (hide)

cpe:2.3:a:smartertools:smartermail:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:47

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/160416/SmarterMail-6985-Remote-Code-Execution.html - () http://packetstormsecurity.com/files/160416/SmarterMail-6985-Remote-Code-Execution.html -
References () http://packetstormsecurity.com/files/173388/SmarterTools-SmarterMail-Remote-Code-Execution.html - () http://packetstormsecurity.com/files/173388/SmarterTools-SmarterMail-Remote-Code-Execution.html -
References () https://www.nccgroup.trust/uk/our-research/technical-advisory-multiple-vulnerabilities-in-smartermail/ - Third Party Advisory () https://www.nccgroup.trust/uk/our-research/technical-advisory-multiple-vulnerabilities-in-smartermail/ - Third Party Advisory
References () https://www.smartertools.com/smartermail/release-notes/current - Exploit, Release Notes, Vendor Advisory () https://www.smartertools.com/smartermail/release-notes/current - Exploit, Release Notes, Vendor Advisory

11 Jul 2023, 18:15

Type Values Removed Values Added
References
  • (MISC) http://packetstormsecurity.com/files/173388/SmarterTools-SmarterMail-Remote-Code-Execution.html -

Information

Published : 2019-04-24 15:29

Updated : 2024-11-21 04:47


NVD link : CVE-2019-7214

Mitre link : CVE-2019-7214

CVE.ORG link : CVE-2019-7214


JSON object : View

Products Affected

smartertools

  • smartermail
CWE
CWE-502

Deserialization of Untrusted Data