« Back to list

Openbsd

Openbsd Opensmtpd: vulnerabilities and CVEs

Openbsd Opensmtpd has 3 published vulnerabilities, 0 of them in the last 12 months. 2 are rated critical and 1 are listed by CISA as actively exploited.

CVEs3
Last 12 months0
Critical2
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2020-7247Critical (9.8)99%⚠ Active exploitationJan 29, 2020
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2020-7247Critical (9.8)99%⚠ Active exploitationJan 29, 2020
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell…
CVE-2015-7687Critical (9.8)4.0%—Oct 16, 2017
Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving req_ca_vrfy_smtp and req_ca_vrfy_mta.
CVE-2013-2125Medium (5)2.5%—May 27, 2014
OpenSMTPD before 5.3.2 does not properly handle SSL sessions, which allows remote attackers to cause a denial of service (connection blocking) by keeping a connection open.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter1
  2. T1190 Exploit Public-Facing Application1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Openbsd