CVE-2020-13376: Path Traversal
Published Aug 7, 2020
·Updated
SecurEnvoy SecurMail 9.3.503 allows attackers to upload executable files and achieve OS command execution via a crafted SecurEnvoyReply cookie.
Affected Software
1 affected component
SecurEnvoy SecurMail=9.3.503
Event History
Aug 7, 2020
CVE Published
via MITRE·07:03 PM
Data Sourced
via MITRE·07:03 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-13376?
CVE-2020-13376 is classified as a high severity vulnerability due to the potential for OS command execution.
2
How do I fix CVE-2020-13376?
To fix CVE-2020-13376, upgrade SecurMail to a version that patches this vulnerability.
3
What systems are affected by CVE-2020-13376?
CVE-2020-13376 affects SecurEnvoy SecurMail version 9.3.503.
4
What type of attack does CVE-2020-13376 enable?
CVE-2020-13376 enables attackers to upload executable files leading to OS command execution.
5
Can CVE-2020-13376 be exploited remotely?
Yes, CVE-2020-13376 can be exploited remotely through a crafted SecurEnvoyReply cookie.