logo

Clash of the (Spam)Titan

ID: 6aa3301f-b7b9-57fc-9b54-780c8d199050

STIX ID: report--6aa3301f-b7b9-57fc-9b54-780c8d199050

Feed Name: SensePost Blog

Threat Score
70/100

Date Published: 2020-07-14

Date Updated: 2026-04-30

...
...

This report documents the discovery and coordinated disclosure of multiple critical vulnerabilities in the SpamTitan appliance (versions ≤7.07), notably an unauthenticated SNMP-based remote code execution (CVE-2020-11698) that can yield root, several authenticated RCEs and an arbitrary file read (CVE-2020-11699, CVE-2020-11700, CVE-2020-11803, CVE-2020-11804), and two console escape flaws affecting VMware tooling and backup import (CVE-2020-24045, CVE-2020-24046). The researcher provides technical analysis, PoCs (including automated exploits), and a disclosure timeline; SpamTitan released fixes in versions 7.08/7.09 and administrators are advised to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.