Skip to content
COOEY

EXPOSURES › CVE-2020-7247

CVE-2020-7247

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-7247 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

A remote code execution flaw in OpenSMTPD allowed attackers to run arbitrary commands as root via a crafted SMTP session.

This RCE vulnerability in OpenSMTPD, used in OpenBSD and other products, enabled remote attackers to execute arbitrary commands as root. DIB organizations must ensure all OpenSMTPD instances are patched immediately, as this flaw was actively exploited in the wild and could lead to full system compromise. The failure highlights the risk of relying on unpatched software, even in critical infrastructure.

Shame score — The vulnerability was actively exploited in the wild and allowed remote code execution as root, indicating a severe and avoidable security failure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.