CVE-2020-12641: Roundcube Roundcube Webmail
EPSS84.3%No. 565 of 1739 in KEV
CVE year2020~3 yrs before listing
Same vendor in KEV11
Same product4
| Field | Value |
|---|---|
| Vendor | Roundcube |
| Product | Roundcube Webmail |
| Name | Roundcube Webmail Remote Code Execution Vulnerability |
| Added to KEV | 2023-06-22 |
| US federal due date | 2023-07-13 |
| Ransomware use | Unknown |
| CWE | CWE-78 |
CISA description
Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
Other entries for this product
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2021-44026 | Roundcube Roundcube Webmail | 2023-06-22 | 69.8% | Unknown |
| CVE-2020-35730 | Roundcube Roundcube Webmail | 2023-06-22 | 32.9% | Unknown |
| CVE-2017-16651 | Roundcube Roundcube Webmail | 2021-11-03 | 45.7% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Roundcube Roundcube Webmail vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2023-06-22.