PT-2016-4833 · Cisco · Cisco Asyncos
Published
2016-10-28
·
Updated
2017-07-29
·
CVE-2016-1486
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco AsyncOS Software versions 9.7.1 through 9.7.1-066
Cisco AsyncOS Software versions 9.7.2 prior to 9.7.2-047
Description
A denial of service (DoS) condition could be triggered by an unauthenticated, remote attacker due to a vulnerability in the email attachment scanning functionality of the Advanced Malware Protection (AMP) feature. This would cause the affected device to stop scanning and forwarding email messages.
Recommendations
For versions 9.7.1 through 9.7.1-066, update to version 9.7.1-207 or later.
For versions 9.7.2 prior to 9.7.2-047, update to version 9.7.2-047 or later.
For all affected versions, ensure the AMP feature is properly configured and consider temporarily disabling the email attachment scanning functionality until the update is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Asyncos