Impact
The vulnerability is a deserialization flaw in the Cmpp7FDeliverRequestMessageCodec component of SMSGate sms-core, allowing a remote attacker to supply crafted data that is deserialized into arbitrary Java objects, which then execute code. This leads to remote code execution on the host. The weakness is a classic instance of unsafe deserialization (CWE‑502).
Affected Systems
The issue affects all deployments of SMSGate sms-core version 2.1.13.6 and earlier. No specific vendor name is documented, but any system that uses this library or component is susceptible.
Risk and Exploitability
Based on the description, it is inferred that the flaw can be exploited without authentication if an attacker can reach the component, for example over a network or message queue interface. The EPSS score is less than 1 % and the vulnerability is not in CISA’s KEV catalog, but the CVSS score of 7.3 indicates high severity. If exploited, the attacker would gain execution privileges equivalent to those of the process running the component, potentially enabling full system compromise.
OpenCVE Enrichment