CVE-2018-12465 is an OS command injection vulnerability in Micro Focus Secure Messaging Gateway (SMG) versions prior to 471, allowing a highly privileged, authenticated remote attacker to execute arbitrary OS commands. This vulnerability can be chained with CVE-2018-12464 for unauthenticated remote code execution. With a CVSS score of 7.2 (HIGH) and an EPSS score indicating high exploitability, it poses a significant risk due to its network-based attack vector and complete compromise potential. While not in CISA's KEV catalog, public exploit code is available via Metasploit and ExploitDB, and it has garnered substantial community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 471CPE matchmatch criteria | cpe:2.3:a:microfocus:secure_messaging_gateway:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.