CVE-2020-7247
KEVHIGH 10.0EPSS 99.0%
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell metacharacters in a MAIL FROM field. This affects the "uncommented" default configuration. The issue exists because of an incorrect return value upon failure of input validation.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 98.97% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-03-25
- Nuclei
- critical · CWE-755
- Published
- 2020-01-29
- Updated
- 2025-10-21
Proof-of-concept exploits (18)
- http://packetstormsecurity.com/files/156137/OpenBSD-OpenSMTPD-Privilege-Escalation-Code-E…
- http://packetstormsecurity.com/files/156145/OpenSMTPD-6.6.2-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/156249/OpenSMTPD-MAIL-FROM-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/156295/OpenSMTPD-6.6.1-Local-Privilege-Escalation.ht…
- http://seclists.org/fulldisclosure/2020/Jan/49
- http://www.openwall.com/lists/oss-security/2020/01/28/3
- FiroSolutions/cve-2020-7247-exploit25★ · 2020-02-19
- G01d3nW01f/SMTPython0★ · 2021-02-02
- Ki11i0n4ir3/SMTPython0★ · 2021-02-02
- QTranspose/CVE-2020-7247-exploit11★ · 2021-02-17
- SimonSchoeni/CVE-2020-7247-POC2★ · 2022-01-20
- SrMeirins/HackingVault3★ · 2026-04-10
- bytescrappers/CVE-2020-72470★ · 2021-02-01
- f4T1H21/CVE-2020-72472★ · 2021-07-10
- minhluannguyen/CVE-2020-7247-reproducer0★ · 2025-03-20
- r0lh/CVE-2020-72475★ · 2020-02-18
- superzerosec/cve-2020-72474★ · 2022-01-15
- solmin111/OpenSMTPD-CVE-2020-7247-
Nuclei templates (1)
Metasploit modules (1)
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/48051
- https://www.exploit-db.com/exploits/48038
- https://www.exploit-db.com/exploits/47984