First published: Wed Feb 19 2020(Updated: )
The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trustwave Mailmarshal | <7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-2727 is critical with a severity value of 9.8.
CVE-2014-2727 is about a vulnerability in the STARTTLS implementation in MailMarshal before version 7.2 that allows plaintext command injection.
Trustwave MailMarshal versions up to exclusive 7.2 are affected by CVE-2014-2727.
The plaintext command injection vulnerability in CVE-2014-2727 can be exploited by an attacker to execute arbitrary commands.
To fix the STARTTLS implementation vulnerability in MailMarshal, update the software to version 7.2 or later as recommended by the vendor.