CVE-2024-5670: Softnext Sn OS
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
The web services of Softnext's products, Mail SQR Expert and Mail Archiving Expert do not properly validate user input, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the remote server.
Affected products
- Softnext Sn OS: version 10.3 only; version 12.1 only; version 12.3 only
Published 2024-07-29. Last modified 2026-06-17.