MIME Header Filtering Bypass in Cisco Email Security Appliances
CVE-2017-3818
5.8MEDIUM
Summary
A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances allows an unauthenticated remote attacker to bypass user-configured filters on the device. This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software, applicable to both virtual and hardware appliances. If the software is set up to apply message or content filters to incoming email attachments, it can be exploited. Users should ensure they upgrade to the appropriate fixed release to mitigate this risk.
Affected Version(s)
Cisco AsyncOS 9.7.1-066 Cisco AsyncOS 9.7.1-066
References
CVSS V3.1
Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved