Blog | G5 Cyber Security

Experts discovered a new critical OpenSMTPD RCE flaw exploited in the wild

Experts discovered a new critical remote code execution vulnerability in the OpenSMTPD that could allow hacking email servers running BSD or Linux. The vulnerability was discovered by researchers from Qualys Research Labs, it is a read issue tracked as CVE-2020-8794. It is an open-source implementation of the server-side SMTP protocol as defined by RFC 5321, it includes also some additional standard extensions. Experts described two attack scenarios related to Client-side exploitation and Server-side. Attackers in the wild started exploiting the issue a few hours its disclosure.”]

Source: https://securityaffairs.co/wordpress/98452/hacking/opensmtpd-rce-flaw.html

Exit mobile version