CVE-2019-7214
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when...
- Published
- Apr 24, 2019
- Updated
- Aug 4, 2024
- Assigning CNA
- mitre
- Evidence observed
- Dec 9, 2020
Primary CVSS
nvd · CVSS 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:CHigh · next 30 days
- Percentile
- 99.5%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely accessible. This port is not accessible remotely by default after applying the Build 6985 patch.
Sources
5- CVE-2019-7214Exploit
Python3 Rewrite of SmarterMail < Build 6985 Remote Code Execution found by 1F98D (CVE-2019-7214) POC
- CVE-2019-7214Exploit
For CTF use only (the CVE-2019-7214 also resolves the host from /etc/hosts)
Exploit code for CVE-2019-7214, a SmarterMail vulnerability, providing proof-of-concept for security testing.
- CVE-2019-7214Exploit
Collection of PoCs created for SmarterMail < Build 6985 RCE
1F98D · windows · Dec 9, 2020
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.