Given Hestia’s reliance on Exim, I’d like to bring to your attention a current vulnerability (CVE-2023-42115) with CVSS score 9.8 that could potentially lead to remote code execution. Unfortunately, there is currently no patch available for this issue. As a temporary solution, we can mitigate the risk by blocking port 25 through the firewall page (iptables) in the HestiaCP panel. It’s important to note that this action will prevent the reception of emails for all email accounts. However, email sending should continue to function without any disruptions.
The email protocol is designed to be resilient and will attempt to send emails multiple times to the same recipient if the mail server cannot be reached (subject to the sender’s mail server configuration). Therefore, if you implement this workaround and the vulnerability is fixed by Monday, emails sent during this period are likely to still be successfully received after removing the Port block.
Current status for Debian and Ubuntu Exim4 packages: