CVE-2014-2727: OS Command Injection
Published Feb 19, 2020
·Updated
The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection.
Affected Software
1 affected component
Trustwave Mailmarshal<7.2
Event History
Feb 19, 2020
CVE Published
via MITRE·01:39 PM
Data Sourced
via MITRE·01:39 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-2727?
The severity of CVE-2014-2727 is critical with a severity value of 9.8.
2
What is CVE-2014-2727 about?
CVE-2014-2727 is about a vulnerability in the STARTTLS implementation in MailMarshal before version 7.2 that allows plaintext command injection.
3
Which software is affected by CVE-2014-2727?
Trustwave MailMarshal versions up to exclusive 7.2 are affected by CVE-2014-2727.
4
How can the plaintext command injection vulnerability be exploited?
The plaintext command injection vulnerability in CVE-2014-2727 can be exploited by an attacker to execute arbitrary commands.
5
How can I fix the STARTTLS implementation vulnerability in MailMarshal?
To fix the STARTTLS implementation vulnerability in MailMarshal, update the software to version 7.2 or later as recommended by the vendor.