Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-59689

Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.209
EPSS Ranking 95.4%
CVSS Severity
CVSS v3 Score 6.1
Proposed Action
Libraesva Email Security Gateway (ESG) contains a command injection vulnerability which allows command injection via a compressed e-mail attachment.
Ransomware Campaign
Unknown
Products affected by CVE-2025-59689


Contact Us

Shodan ® - All rights reserved