CVE-2020-12782: Openfind MailGates - Command Injection
Published Jun 23, 2020
·Updated
Openfind MailGates contains a Command Injection flaw, when receiving email with specific strings, malicious code in the mail attachment will be triggered and gain unauthorized access to system files.
Affected Software
2 affected components
Openfind MailAudit=5.0
Openfind MailGates=5.0
Remediation
Information
Update to version 5.2.7.036, or contact with Openfind.
Event History
Jun 23, 2020
CVE Published
via MITRE·06:05 AM
Data Sourced
via MITRE·06:05 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-12782?
CVE-2020-12782 is a Command Injection flaw in Openfind MailGates that allows unauthorized access to system files.
2
How does CVE-2020-12782 work?
CVE-2020-12782 is triggered when receiving an email with specific strings, allowing malicious code in the mail attachment to gain unauthorized access to system files.
3
Which software versions are affected by CVE-2020-12782?
Openfind Mailaudit 5.0 and Openfind MailGates 5.0 are affected by CVE-2020-12782.
4
What is the severity of CVE-2020-12782?
CVE-2020-12782 is classified as critical with a severity rating of 9.8.
5
How can I fix CVE-2020-12782?
Patch or upgrade Openfind Mailaudit and Openfind MailGates to a version that addresses the Command Injection flaw.