HTTP: Micro Focus Secure Messaging Gateway Command Injection

This signature detects attempts to exploit a known vulnerability against Micro Focus Secure Messaging Gateway. A successful attack can lead to command injection and arbitrary code execution.

Extended Description

DKIM key management page vulnerability on Micro Focus Secure Messaging Gateway (SMG). Affecting all SMG Appliance running releases prior to July 2020. The vulnerability could allow a logged in user with rights to generate DKIM key information to inject system commands into the call to the DKIM system command.

Affected Products

Microfocus secure_messaging_gateway

References

CVE: CVE-2020-11852

Short Name
HTTP:CTS:MICRO-FOCUS-SMG-CMDINJ
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2020-11852 Command Focus Gateway Injection Messaging Micro Secure
Release Date
09/30/2020
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Microfocus

CVSS Score

9.0

Found a potential security threat?