Junglewise Threat Intelligence

CVE-2020-7247: OpenSMTPD Remote Code Execution Vulnerability

CVE-2020-7247 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-25

Technologies: Openbsd. Vendors: OpenBSD.

Executive brief

A remote code execution vulnerability exists in OpenSMTPD's smtp_mailaddr function due to incorrect input validation of the MAIL FROM field. Attackers can exploit this via shell metacharacters in a crafted SMTP session to execute arbitrary commands as root in the default configuration.

Affected products

  • OpenBSD OpenSMTPD 6.6
  • OpenBSD OpenBSD 6.6

Timeline

  • 2020-01-28: disclosed: Initial public disclosure via Openwall and Seclists
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-25: exploited: Confirmed as exploited in the wild per CISA KEV entry