Email Security Appliances Vulnerability in Cisco AsyncOS Software
CVE-2016-1481

7.5HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
28 October 2016

Summary

A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Email Security Appliances allows unauthenticated remote attackers to exploit specific rules in configured message filters, potentially leading to a denial of service (DoS) condition on affected devices. This issue affects all software releases before the first fixed versions, threatening both virtual and hardware appliances when message filtering is enabled. Known affected versions include 8.5.6-106, 9.1.0-032, and 9.7.0-125, while the fixed releases are 9.1.1-038 and 9.7.1-066.

Affected Version(s)

Cisco AsyncOS through 9.7.0-125 Cisco AsyncOS through 9.7.0-125

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.