CVE-2024-5670: Softnext Sn OS

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

The web services of Softnext's products, Mail SQR Expert and Mail Archiving Expert do not properly validate user input, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the remote server.

Affected products

  • Softnext Sn OS: version 10.3 only; version 12.1 only; version 12.3 only

Published 2024-07-29. Last modified 2026-06-17.