ZIP Filtering Bypass in Cisco Email Security Appliance
CVE-2014-3381

Currently unrated

Key Information:

Vendor
Cisco
Status
Vendor
CVE Published:
19 October 2014

Summary

The ZIP inspection engine in Cisco AsyncOS versions 8.5 and earlier on the Cisco Email Security Appliance (ESA) has a significant vulnerability that allows remote attackers to exploit its inability to properly analyze ZIP archives. This flaw facilitates a bypass of malware filtering mechanisms, thereby enabling potentially malicious files to evade detection through crafted ZIP archives. Organizations utilizing affected versions should implement necessary security measures to mitigate the risk associated with this vulnerability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.