Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14683 | GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue. A remote and authenticated attacker can execute arbitrary code by sending crafted serialized .NET when joining to a Multi-Server setup. |
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 04 Nov 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | GFI MailEssentials MultiNode Insecure Deserialization | GFI MailEssentials < 21.8 MultiNode Insecure Deserialization |
Sat, 10 May 2025 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gfi
Gfi mailessentials |
|
| CPEs | cpe:2.3:a:gfi:mailessentials:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gfi
Gfi mailessentials |
Mon, 28 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Apr 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue. A remote and authenticated attacker can execute arbitrary code by sending crafted serialized .NET when joining to a Multi-Server setup. | |
| Title | GFI MailEssentials MultiNode Insecure Deserialization | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-11-19T01:25:57.239Z
Reserved: 2025-04-15T19:15:22.611Z
Link: CVE-2025-34491
Updated: 2025-04-28T19:41:03.433Z
Status : Modified
Published: 2025-04-28T20:15:20.997
Modified: 2025-11-04T23:15:37.043
Link: CVE-2025-34491
No data.
OpenCVE Enrichment
No data.
EUVD