CVE-2018-6289
CRITICALKaspersky Secure Mail Gateway 1.1 - Configuration File Injection Leading to Remote Code Execution
Title source: llmDescription
Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://support.kaspersky.com/vulnerability.aspx?el=12430#010218
Exploit, Technical Description, Third Party Advisory x_refsource_misc
https://www.coresecurity.com/advisories/kaspersky-secure-mail-gateway-multiple-vulnerabilities
Scores
CVSS v3
9.8
EPSS
0.0672
EPSS Percentile
93.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-74
Status
published
Products (1)
kaspersky/secure_mail_gateway
1.1
Published
Feb 06, 2018
Tracked Since
Feb 18, 2026