Описание
Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7.
Ссылки
- Vendor Advisory
- Vendor Advisory
- US Government Resource
Уязвимые конфигурации
Конфигурация 1Версия от 4.5 (включая) до 5.0.31 (исключая)Версия от 5.1.0 (включая) до 5.1.20 (исключая)Версия от 5.2.0 (включая) до 5.2.31 (исключая)Версия от 5.3.0 (включая) до 5.3.16 (исключая)Версия от 5.4.0 (включая) до 5.4.8 (исключая)Версия от 5.5.0 (включая) до 5.5.7 (исключая)
Одно из
cpe:2.3:a:libraesva:email_security_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:libraesva:email_security_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:libraesva:email_security_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:libraesva:email_security_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:libraesva:email_security_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:libraesva:email_security_gateway:*:*:*:*:*:*:*:*
EPSS
Процентиль: 90%
0.05179
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-77
Связанные уязвимости
CVSS3: 6.1
github
5 месяцев назад
Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7.
EPSS
Процентиль: 90%
0.05179
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-77