PoC Index

CVE-2019-7214

HIGH 10.0EPSS 84.8%

SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely accessible. This port is not accessible remotely by default after applying the Build 6985 patch.

CVSS v3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
84.82% chance of exploitation in the next 30 days, 100th percentile
Published
2019-04-24
Updated
2024-08-04

Proof-of-concept exploits (4)

Metasploit modules (1)

ExploitDB entries (1)

References

Related