Content Filtering Bypass in Cisco Email Security Appliances
CVE-2016-6458
7.5HIGH
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 19 November 2016
Summary
A flaw in the content filtering mechanism of Cisco AsyncOS Software for Email Security Appliances could allow unauthorized remote attackers to evade established email content filters. This vulnerability affects virtual and hardware appliances that utilize content filtering for protected or encrypted email attachments, potentially allowing harmful content to bypass security checks and be delivered to recipients.
Affected Version(s)
Cisco AsyncOS 10.0.0-125 and 9.7.1-066 Cisco AsyncOS 10.0.0-125 and 9.7.1-066
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved