S4E just found a medium vulnerable javascript library scanner
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-7247 Scanner

Detects 'Remote Code Execution (RCE)' vulnerability in OpenSMTPD affects v. 6.6.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2020-7247
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell metacharacters in a MAIL FROM field. This affects the "uncommented" default configuration. The issue exists because of an incorrect return value upon failure of input validation.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 5, 2026View on NVD →
Detail

OpenSMTPD is a popular mail transfer agent used by various products, including OpenBSD 6.6. The main purpose of this product is to transfer emails between servers and clients in a secure manner. It is widely used by system administrators for maintaining reliable email communication channels for their organizations. OpenSMTPD has a simple architecture that makes it easy to use, configure, and maintain. 

Recently, a serious vulnerability was detected in this widely used product. The vulnerability identified as CVE-2020-7247 allows remote attackers to execute arbitrary commands as root via a crafted SMTP session. This occurs due to an incorrect return value upon failure of input validation. Hackers can exploit this vulnerability to trigger shell metacharacters in the MAIL FROM field and execute commands on the targeted email server.

If the CVE-2020-7247 vulnerability is exploited, it could result in an improper gain of privilege within the targeted email server. The attacker could misuse the gained root-level access to modify system files, steal data, initiate a ransomware attack, or even cause a denial of service (DoS) attack. Furthermore, attackers could use this vulnerability for controlled execution of malicious code and launch a worm or other types of malware across the network. Thus, the CVE-2020-7247 vulnerability poses significant threats to the overall security of digital assets.

In conclusion, vulnerabilities such as CVE-2020-7247 are a real threat in the digital age, and it is imperative to take swift and proactive measures against them. As a cybersecurity platform that emphasizes pro features, s4e.io provides users with regular updates on detected vulnerabilities and provides insights into the latest cybersecurity trends and threats. It is the go-to platform for organizations seeking to enhance their cybersecurity posture and protect their digital assets from ever-evolving cyber threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is highly recommended to take the following precautions: 

  • Update OpenSMTPD to the latest version 
  • Restrict the inputs that are allowed for SMTP sessions 
  • Implement firewalls to limit access to sensitive systems 
  • Monitor email logs and activity regularly 
  • Deploy security solutions at the edge of the network to block malicious traffic 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-7247 scanner - Remote Code Execution (RCE) vulnerability in OpenSMTPD S4E