Content Filtering Bypass in Cisco Email Security Appliances
CVE-2016-6458

7.5HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
19 November 2016

Summary

A flaw in the content filtering mechanism of Cisco AsyncOS Software for Email Security Appliances could allow unauthorized remote attackers to evade established email content filters. This vulnerability affects virtual and hardware appliances that utilize content filtering for protected or encrypted email attachments, potentially allowing harmful content to bypass security checks and be delivered to recipients.

Affected Version(s)

Cisco AsyncOS 10.0.0-125 and 9.7.1-066 Cisco AsyncOS 10.0.0-125 and 9.7.1-066

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.