Loading HuntDB...

Libraesva Email Security Gateway Command Injection Vulnerability

Added Sept. 29, 2025 Due Oct. 20, 2025 CVE-2025-59689
On Track Libraesva / Email Security Gateway CWE-77

Description

Libraesva Email Security Gateway (ESG) contains a command injection vulnerability which allows command injection via a compressed e-mail attachment.

Required Action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

References

Additional Information

Catalog Version
2025.09.29
Catalog Released
Sept. 29, 2025
Days Until Due
11 days
Last Updated
1 week, 2 days ago