EXPOSURES › CVE-2020-7247
CVE-2020-7247
HIGH ⌖ ON CISA KEV · EXPLOITEDA remote code execution flaw in OpenSMTPD allowed attackers to run arbitrary commands as root via a crafted SMTP session.
This RCE vulnerability in OpenSMTPD, used in OpenBSD and other products, enabled remote attackers to execute arbitrary commands as root. DIB organizations must ensure all OpenSMTPD instances are patched immediately, as this flaw was actively exploited in the wild and could lead to full system compromise. The failure highlights the risk of relying on unpatched software, even in critical infrastructure.
Shame score — The vulnerability was actively exploited in the wild and allowed remote code execution as root, indicating a severe and avoidable security failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session.