MIME Header Filtering Bypass in Cisco Email Security Appliances
CVE-2017-3818

5.8MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
3 February 2017

Summary

A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances allows an unauthenticated remote attacker to bypass user-configured filters on the device. This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software, applicable to both virtual and hardware appliances. If the software is set up to apply message or content filters to incoming email attachments, it can be exploited. Users should ensure they upgrade to the appropriate fixed release to mitigate this risk.

Affected Version(s)

Cisco AsyncOS 9.7.1-066 Cisco AsyncOS 9.7.1-066

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.