CVE-2019-7212: High severity smartertools smartermail enterprise vulnerability
Published Apr 24, 2019
·Updated
SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access other users’ emails and file attachments. It was also possible to interact with mailing lists.
Affected Software
1 affected component
SmarterTools SmarterMail>=16.0.6345<16.3.6985
Event History
Apr 24, 2019
CVE Published
via MITRE·02:43 PM
Data Sourced
via MITRE·02:43 PM
Description
Data Sourced
via NVD·03:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-7212.
2
What is the severity of CVE-2019-7212?
The severity of CVE-2019-7212 is high with a CVSS score of 8.2.
3
How does CVE-2019-7212 affect SmarterTools SmarterMail?
CVE-2019-7212 affects SmarterTools SmarterMail versions 16.x before build 6985 by allowing an unauthenticated attacker to access other users' emails and file attachments, as well as interact with mailing lists.
4
How can an attacker exploit CVE-2019-7212?
An attacker can exploit CVE-2019-7212 by leveraging the hardcoded secret keys in SmarterMail to gain unauthorized access.
5
Is there a fix available for CVE-2019-7212?
Yes, SmarterTools has released a fix for CVE-2019-7212 in build 6985 of SmarterMail 16.x.