ZIP Filtering Bypass in Cisco Email Security Appliance
CVE-2014-3381
Currently unrated
Summary
The ZIP inspection engine in Cisco AsyncOS versions 8.5 and earlier on the Cisco Email Security Appliance (ESA) has a significant vulnerability that allows remote attackers to exploit its inability to properly analyze ZIP archives. This flaw facilitates a bypass of malware filtering mechanisms, thereby enabling potentially malicious files to evade detection through crafted ZIP archives. Organizations utilizing affected versions should implement necessary security measures to mitigate the risk associated with this vulnerability.
References
Timeline
Vulnerability published
Vulnerability Reserved