Openbsd Opensmtpd - Improper Exception Handling
Title source: ruleDescription
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell metacharacters in a MAIL FROM field. This affects the "uncommented" default configuration. The issue exists because of an incorrect return value upon failure of input validation.
Exploits (15)
exploitdb
WORKING POC
VERIFIED
by Marco Ivaldi · perlremoteopenbsd
https://www.exploit-db.com/exploits/48051
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/48038
exploitdb
WORKING POC
VERIFIED
by 1F98D · pythonremotelinux
https://www.exploit-db.com/exploits/47984
nomisec
WORKING POC
25 stars
by FiroSolutions · poc
https://github.com/FiroSolutions/cve-2020-7247-exploit
nomisec
WORKING POC
11 stars
by QTranspose · remote
https://github.com/QTranspose/CVE-2020-7247-exploit
nomisec
WORKING POC
2 stars
by presentdaypresenttime · poc
https://github.com/presentdaypresenttime/shai_hulud
nomisec
WORKING POC
2 stars
by SimonSchoeni · remote
https://github.com/SimonSchoeni/CVE-2020-7247-POC
nomisec
WORKING POC
1 stars
by minhluannguyen · remote
https://github.com/minhluannguyen/CVE-2020-7247-reproducer
metasploit
WORKING POC
EXCELLENT
by Qualys, wvu · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/smtp/opensmtpd_mail_from_rce.rb
Nuclei Templates (1)
OpenSMTPD 6.4.0-6.6.1 - Remote Code Execution
CRITICALby princechaddha
References (15)
Scores
CVSS v3
9.8
EPSS
0.9408
EPSS Percentile
99.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Lab Environment
COMMUNITY
Community Lab
+8 more repos
Details
CISA KEV
2022-03-25
VulnCheck KEV
2022-03-25
InTheWild.io
2020-01-31
ENISA EUVD
EUVD-2020-28374
CWE
CWE-78
CWE-755
Status
published
Products (6)
canonical/ubuntu_linux
18.04
canonical/ubuntu_linux
19.10
debian/debian_linux
9.0
debian/debian_linux
10.0
fedoraproject/fedora
32
openbsd/opensmtpd
6.6
Published
Jan 29, 2020
KEV Added
Mar 25, 2022
Tracked Since
Feb 18, 2026