Vulnerability record · CVE-2019-7214 · published 24 April 2019
CVE-2019-7214: SmarterMail deserialization of untrusted data enables unauthenticated RCE
Smartertools · Smartermail
SmarterTools SmarterMail 16.x before build 6985 deserializes untrusted data, letting an unauthenticated attacker execute commands on the server when port 17001 is remotely reachable. The port is not remotely accessible by default once the Build 6985 patch is applied, so exposure depends on whether that port was left open.
Description
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely accessible. This port is not accessible remotely by default after applying the Build 6985 patch.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required and very high EPSS, though real-world exposure is limited to hosts with port 17001 reachable.
What it is
SmarterTools SmarterMail 16.x before build 6985 deserializes untrusted data, letting an unauthenticated attacker execute commands on the server when port 17001 is remotely reachable. The port is not remotely accessible by default once the Build 6985 patch is applied, so exposure depends on whether that port was left open.
Impact
An attacker gains remote code execution on the mail server with no credentials, giving full control of the host and any mail data or credentials it holds.
Attack surface
Reached over the network via port 17001; the CVSS vector shows no privileges and no user interaction required. Exploitation is only possible where that port is remotely accessible, which the vendor states is not the default after the patch.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.848, ~99.7th percentile) and references include an exploit-tagged vendor release note plus public Packet Storm RCE write-ups, indicating public exploit code exists.
What to do
- Upgrade SmarterMail to build 6985 or later, which closes remote access to port 17001.
- Block port 17001 at the perimeter and host firewall; restrict it to trusted management hosts only.
- If the port must remain reachable, place it behind a VPN or authenticated jump host.
- Audit for prior compromise on hosts that had port 17001 exposed before patching.
Detection
- Monitor network flows and firewall logs for inbound connections to TCP 17001 from external addresses.
- Alert on unexpected child processes spawned by the SmarterMail service, especially shells or scripting interpreters.
- Review SmarterMail and OS logs for anomalous command execution or service restarts around the time of port 17001 connections.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-7214 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-7214), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.