PT-2016-6930 · Cisco · Cisco Email Security Appliances+1

Publicado

2016-11-19

·

Atualizado

2017-07-29

·

CVE-2016-6458

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cisco Email Security Appliances versions prior to the first fixed release
Description A vulnerability in the content filtering functionality could allow an unauthenticated, remote attacker to bypass content filters configured on an affected device, potentially causing email that should have been filtered to be forwarded instead. This issue affects devices configured to use a content filter for email attachments that are protected or encrypted.
Recommendations For versions prior to the first fixed release, update to the first fixed release of Cisco AsyncOS Software to resolve the issue. As a temporary workaround, consider disabling the content filtering functionality for email attachments that are protected or encrypted until a patch is available. Restrict access to the content filtering module to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-6458

Produtos afetados

Cisco Asyncos
Cisco Email Security Appliances