CVE-2020-12713: Ciphermail Gateway

High severity, CVSS 7.2. EPSS: 2.6% chance of exploitation in the next 30 days.

An issue was discovered in CipherMail Community Gateway and Professional/Enterprise Gateway 1.0.1 through 4.7.1-0 and CipherMail Webmail Messenger 1.1.1 through 3.1.1-0. Attackers with administrative access to the web interface have multiple options to escalate their privileges to the Unix root account.

Affected products

  • Ciphermail Gateway: from 1.0.1, up to and including 4.7.1-0
  • Ciphermail Webmail Messenger: from 1.1.1, up to and including 3.1.1-0

Published 2020-06-11. Last modified 2026-06-17.