PT-2018-1815 · Cisco · Cisco Email Security Appliances

Published

2018-08-15

·

Updated

2019-10-09

·

CVE-2018-0419

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco Email Security Appliances (ESA) (affected versions not specified)
Description A vulnerability in the attachment detection mechanisms of Cisco Email Security Appliances could allow an unauthenticated, remote attacker to bypass the filtering functionality of an affected system. The issue is due to the improper detection of content within executable (EXE) files. An attacker could exploit this by sending a customized EXE file that is not recognized and blocked by the ESA. A successful exploit could allow an attacker to send email messages that contain malicious executable files to unsuspecting users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-01415
CVE-2018-0419

Affected Products

Cisco Email Security Appliances