CRITICAL

CVE-2020-8794

CVSS v3

9.8

CRITICAL

EPSS Score

88.1%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to attack a server because the server code launches the client code during bounce handling.

Technical details

Published
2/25/2020

Frequently asked questions

What is CVE-2020-8794?

OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to attack a server because the server code launches the client code during bounce handling.

Is CVE-2020-8794 actively exploited?

Active exploitation of CVE-2020-8794 has not been confirmed. The EPSS score is 88.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-8794?

CVE-2020-8794 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2020-8794 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.