Denial of Service Vulnerability in Cisco Email Security Appliances
CVE-2016-6356
7.5HIGH
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 28 October 2016
Summary
A vulnerability exists in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances. This flaw could enable an unauthenticated, remote attacker to trigger a denial of service condition, thereby halting the device's ability to scan and forward email messages. The issue arises when the software is configured to apply message or content filters to incoming email attachments. It affects all pre-fixed releases and is not specific to any rules for filtering.
Affected Version(s)
Cisco AsyncOS through 9.7.0-125 Cisco AsyncOS through 9.7.0-125
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved