PT-2025-32399 · Unknown · E-Mail Security Virtual Appliance

Published

2025-08-08

·

Updated

2025-08-08

·

CVE-2012-10046

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions: E-Mail Security Virtual Appliance (ESVA) version ESVA 2057
Description: The E-Mail Security Virtual Appliance (ESVA) contains an unauthenticated command injection issue in the learn-msg.cgi script. The CGI handler does not properly sanitize user-supplied input provided through the id parameter, which allows attackers to inject arbitrary shell commands. Exploitation does not require authentication and results in full command execution on the underlying system.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2012-10046

Affected Products

E-Mail Security Virtual Appliance