Impact
NUMail, the email platform from Green-Computing, has an OS Command Injection flaw that allows unauthenticated remote attackers to supply crafted input that is directly passed to the operating system for execution. This vulnerability can be leveraged to run arbitrary shell commands on the server, giving an attacker complete control over the affected system and compromising its confidentiality, integrity and availability.
Affected Systems
The flaw affects Green-Computing’s NUMail email platform. Any instance running a version released before 202602162 is impacted; the vendor has issued a patch with version 202602162 or later that resolves the issue.
Risk and Exploitability
The CVSS score of 9.3 classifies the flaw as critical. The EPSS score of 1% indicates a low but non-zero probability of exploitation. The vulnerability is not listed in CISA KEV. Attackers can reach the vulnerable input via the publicly exposed service without authentication. If exploited, the flaw could lead to full system compromise, but the low EPSS suggests that exploitation in the wild is unlikely at present.
OpenCVE Enrichment