Cisco Email Security Appliance Zip Decompression Engine Denial of Service Vulnerability
CVE-2020-3134
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 26 January 2020
What is CVE-2020-3134?
A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper validation of zip files. An attacker could exploit this vulnerability by sending an email message with a crafted zip-compressed attachment. A successful exploit could trigger a restart of the content-scanning process, causing a temporary DoS condition. This vulnerability affects Cisco AsyncOS Software for Cisco ESA releases earlier than 13.0.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Email Security Appliance (ESA) earlier than 13.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved