ID

VAR-202111-0982


CVE

CVE-2021-32234


TITLE

SmarterTools SmarterMail  Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2021-015053

DESCRIPTION

SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows remote code execution. SmarterTools SmarterMail Exists in unspecified vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. SmarterMail is an award-winning email, collaboration and group chat server that can easily meet the needs of businesses of any size, from individual owners to large companies and corporate organizations. With lower hardware requirements, excellent stability and lower maintenance costs, SmarterMail's TCO has been significantly reduced, making it a first-class Microsoft Exchange alternative for enterprises and hosting companies. Attackers can use this vulnerability to execute attack code

Trust: 2.16

sources: NVD: CVE-2021-32234 // JVNDB: JVNDB-2021-015053 // CNVD: CNVD-2021-91631

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-91631

AFFECTED PRODUCTS

vendor:smartertoolsmodel:smartermailscope:gteversion:16.0.6345

Trust: 1.0

vendor:smartertoolsmodel:smartermailscope:ltversion:100.0.7803

Trust: 1.0

vendor:smartertoolsmodel:smartermailscope:ltversion:6.x from 100.x

Trust: 0.8

vendor:smartertoolsmodel:smartermailscope:eqversion:100.0.7803

Trust: 0.8

vendor:smartertoolsmodel:smartermailscope:eqversion: -

Trust: 0.8

vendor:smartertoolsmodel:smartermailscope:gteversion:16.0.6345,<100.0.7803

Trust: 0.6

sources: CNVD: CNVD-2021-91631 // JVNDB: JVNDB-2021-015053 // NVD: CVE-2021-32234

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-32234
value: CRITICAL

Trust: 1.0

NVD: CVE-2021-32234
value: CRITICAL

Trust: 0.8

CNVD: CNVD-2021-91631
value: HIGH

Trust: 0.6

CNNVD: CNNVD-202111-1543
value: CRITICAL

Trust: 0.6

nvd@nist.gov: CVE-2021-32234
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2021-91631
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 8.5
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2021-32234
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2021-32234
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2021-91631 // JVNDB: JVNDB-2021-015053 // CNNVD: CNNVD-202111-1543 // NVD: CVE-2021-32234

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:Lack of information (CWE-noinfo) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-015053 // NVD: CVE-2021-32234

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202111-1543

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202111-1543

PATCH

title:SmarterMail Release Notes and Version Historyurl:https://www.smartertools.com/smartermail/release-notes/current

Trust: 0.8

title:Patch for SmarterMail remote code execution vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/301056

Trust: 0.6

title:Smartertools SmarterTools SmarterMail Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=170523

Trust: 0.6

sources: CNVD: CNVD-2021-91631 // JVNDB: JVNDB-2021-015053 // CNNVD: CNNVD-202111-1543

EXTERNAL IDS

db:NVDid:CVE-2021-32234

Trust: 3.8

db:JVNDBid:JVNDB-2021-015053

Trust: 0.8

db:CNVDid:CNVD-2021-91631

Trust: 0.6

db:CNNVDid:CNNVD-202111-1543

Trust: 0.6

sources: CNVD: CNVD-2021-91631 // JVNDB: JVNDB-2021-015053 // CNNVD: CNNVD-202111-1543 // NVD: CVE-2021-32234

REFERENCES

url:https://csirt.divd.nl/cases/divd-2021-00006/

Trust: 2.4

url:https://nvd.nist.gov/vuln/detail/cve-2021-32234

Trust: 2.0

url:https://www.smartertools.com/smartermail/release-notes/current

Trust: 1.6

sources: CNVD: CNVD-2021-91631 // JVNDB: JVNDB-2021-015053 // CNNVD: CNNVD-202111-1543 // NVD: CVE-2021-32234

SOURCES

db:CNVDid:CNVD-2021-91631
db:JVNDBid:JVNDB-2021-015053
db:CNNVDid:CNNVD-202111-1543
db:NVDid:CVE-2021-32234

LAST UPDATE DATE

2024-08-14T13:43:14.076000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-91631date:2021-11-26T00:00:00
db:JVNDBid:JVNDB-2021-015053date:2022-11-08T06:49:00
db:CNNVDid:CNNVD-202111-1543date:2021-11-30T00:00:00
db:NVDid:CVE-2021-32234date:2021-11-18T21:30:10.737

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-91631date:2021-11-26T00:00:00
db:JVNDBid:JVNDB-2021-015053date:2022-11-08T00:00:00
db:CNNVDid:CNNVD-202111-1543date:2021-11-17T00:00:00
db:NVDid:CVE-2021-32234date:2021-11-17T17:15:08.137