Impact
The flaw is an insecure deserialization vulnerability in the MailReceiver component of lenve vhr 1.0-SNAPSHOT, allowing an attacker to send crafted input that is deserialized without proper validation. This can lead to arbitrary code execution or other malicious actions on the host. The weakness is a classic unserialization flaw (CWE-502) coupled with insufficient input validation (CWE-20).
Affected Systems
Lenve VHR 1.0-SNAPSHOT is affected by this issue. The security flaw specifically lies within the MailReceiver component of the product.
Risk and Exploitability
The CVSS score of 5.3 denotes moderate severity, but the public release of an exploit and the ability to attack remotely raise concerns. EPSS is <1%, indicating a very low yet nonzero exploitation probability, though the existence of a published exploit implies a realistic threat. This vulnerability is not listed in CISA's KEV catalog, but the remote nature of the attack and the lack of vendor response suggest it could serve as a foothold for further compromise.
OpenCVE Enrichment