CISA Known Exploited Vulnerability

CVE-2020-7247

OpenBSD · OpenSMTPD

OpenSMTPD Remote Code Execution Vulnerability

Date added
BOD 22-01 due date
CWE CWE-755, CWE-78
Ransomware Unknown

CISA description

smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session.

Required action

Apply updates per vendor instructions.