Remote Code Execution Vulnerability in Cisco Email Security Appliance and Web Security Appliance
CVE-2016-1411
5.9MEDIUM
What is CVE-2016-1411?
A flaw exists in the update functionality of Cisco AsyncOS Software used in Cisco Email Security Appliance (ESA) and Cisco Web Security Appliance (WSA) that allows an unauthenticated remote attacker to impersonate the update server. This may lead to unauthorized access, allowing attackers to execute malicious updates or code. Several versions are affected, and it is crucial for users to apply the recommended fixes available in the newer releases.
Affected Version(s)
Cisco AsyncOS Cisco AsyncOS