Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: May 19, 2025

CVE-2025-42599

High
EPSS 2.8%CISA KEV
Qualitia/Active! Mail

Description

Qualitia Active! Mail contains a stack-based buffer overflow vulnerability that allows a remote, unauthenticated attacker to execute arbitrary or trigger a denial-of-service via a specially crafted request.

EPSS — Exploit Probability

2.8%

Higher than 85.8% of all CVEs

Required Action

https://www.qualitia.com/jp/news/2025/04/18_1030.html ; https://nvd.nist.gov/vuln/detail/CVE-2025-42599

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
2.8%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Apr 28, 2025

Added to KEV

Apr 28, 2025

Remediation Due

May 19, 2025

Affected Product

Qualitia

Active! Mail

View all Qualitia CVEs