Critical severity9.8NVD Advisory· Published Jul 29, 2024· Updated Jun 17, 2026
CVE-2024-5670
CVE-2024-5670
Description
The web services of Softnext's products, Mail SQR Expert and Mail Archiving Expert do not properly validate user input, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the remote server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:o:softnext:sn_os:10.3:-:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:softnext:sn_os:10.3:-:*:*:*:*:*:*
- cpe:2.3:o:softnext:sn_os:12.1:-:*:*:*:*:*:*
- cpe:2.3:o:softnext:sn_os:12.3:-:*:*:*:*:*:*
- Range: 0
Patches
Vulnerability mechanics
References
2- www.twcert.org.tw/en/cp-139-7959-09d0e-2.htmlnvdThird Party Advisory
- www.twcert.org.tw/tw/cp-132-7958-817f4-1.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.