Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-8794

OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to attack a server because the server code launches the client code during bounce handling.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.868
EPSS Ranking 99.4%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 10.0
References
Products affected by CVE-2020-8794


Contact Us

Shodan ® - All rights reserved