CVE-2020-7247 is a critical vulnerability in OpenSMTPD (the mail server used by OpenBSD and other systems) affecting versions since May 2018. The vulnerability resides in the smtp_mailaddr() function in smtp_session.c, which fails to properly validate input in the MAIL FROM field of SMTP sessions. This allows remote attackers to inject shell metacharacters and execute arbitrary commands as root during mail delivery, leveraging the mail delivery agent (MDA) process. The flaw is present in the default and 'uncommented' default configurations and can be exploited both locally and remotely, depending on the server's configuration.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a small standalone proof-of-concept for CVE-2020-7247, an OpenSMTPD remote command execution vulnerability. It contains three files: a README describing the vulnerability and lab steps, a docker-compose.yml that launches a vulnerable vulhub/opensmtpd:6.6.1p1 container with host port 8825 mapped to container port 25, and poc.py, the actual exploit script. The exploit logic in poc.py is straightforward and fully functional. It opens a TCP socket to a user-supplied target IP and port, verifies the SMTP banner contains 'OpenSMTPD', performs a basic SMTP handshake with 'HELO x', and then sends a malicious MAIL FROM command of the form 'MAIL FROM:<;CMD;>' where CMD is attacker-controlled. This abuses insufficient input sanitization in vulnerable OpenSMTPD versions before 6.6.2, causing arbitrary shell command execution on the server. The script then completes the SMTP transaction with RCPT TO, DATA, and QUIT commands. Capabilities are limited to arbitrary command execution via SMTP and do not include post-exploitation automation, persistence, or interactive shell management. Because the payload is directly supplied as a command-line argument and inserted into the SMTP envelope, this is best classified as an operational PoC rather than a framework-integrated or heavily weaponized exploit. The repository’s purpose is educational and reproducible lab validation: the README walks through starting the vulnerable container, connecting to the SMTP service on 127.0.0.1:8825, running the PoC with a benign command such as 'touch /tmp/proof.txt', and verifying successful execution inside the container.
This repository provides a full environment and exploit for CVE-2020-7247, a remote command execution vulnerability in OpenSMTPD 6.6.1p1. The repository includes Docker and Nix files to build a vulnerable OpenSMTPD instance, along with configuration files (smtpd.conf, aliases, etc.) to set up the environment. The main exploit is implemented in 'exploit.py', which connects to the SMTP service (default IP 172.17.0.2, port 25) and sends a specially crafted SMTP session. The exploit abuses the 'MAIL FROM' field to inject shell commands, ultimately sending a payload that spawns a reverse shell back to the attacker's machine (default IP 172.17.0.1, port 8080). The exploit is operational and provides remote root shell access if successful. The repository is well-structured for both demonstration and testing, with clear instructions in the README for building the environment and running the exploit.
This repository contains a single Metasploit module: 'OpenSMTPD MAIL FROM Remote Code Execution' (modules/exploits/unix/smtp/opensmtpd_mail_from_rce.rb). The module exploits a command injection vulnerability (CVE-2020-7247) in the MAIL FROM field of the SMTP protocol as implemented by OpenSMTPD versions 6.4.0 to 6.6.1. By sending a specially crafted MAIL FROM value during an SMTP session, the attacker can execute arbitrary shell commands as root on the target system. The exploit is operational and leverages the Metasploit framework's payload system, defaulting to a reverse netcat shell. The only required input is a valid recipient email address (default: root). The attack vector is network-based, targeting TCP port 25 (SMTP). The code is written in Ruby and is structured as a standard Metasploit exploit module, with options for target port, recipient, and timeout. No hardcoded IPs, domains, or file paths are present; the exploit is generic and adaptable to any vulnerable OpenSMTPD instance.
This repository contains a proof-of-concept exploit for CVE-2020-7247, a remote command execution vulnerability in OpenSMTPD versions prior to 6.6.2. The main file, CVE-2020-7247.go, is a Go program that connects to a target OpenSMTPD server over TCP (default port 25), verifies the banner, and sends a crafted SMTP payload that exploits the vulnerability to execute arbitrary shell commands. The payload establishes a reverse shell from the target server to the attacker's machine using netcat. The exploit requires the attacker to specify the target's address, port, domain, and their own IP and port for the reverse shell. The README provides usage instructions and credits. The exploit is a functional proof-of-concept and not weaponized, as the payload and listener must be manually configured.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.