Skip to content
COOEY

EXPOSURES › CVE-2020-12641

CVE-2020-12641

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-06-22 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-12641 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Roundcube Webmail Remote Code Execution Vulnerability exposed in 84,000 servers

An actively exploited remote code execution vulnerability in Roundcube Webmail allows attackers to execute arbitrary code. This poses a significant risk to over 84,000 servers, impacting network security and data integrity. DIB organizations should ensure their systems are patched and monitored for this vulnerability.

Shame score — The vulnerability was actively exploited, affecting a large number of servers and posing a significant risk to network security.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.