PT-2020-1574 · Cisco · Cisco Asyncos+1

Published

2020-01-22

·

Updated

2020-01-28

·

CVE-2020-3134

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Cisco AsyncOS Software for Cisco Email Security Appliance versions prior to 13.0
Description A vulnerability in the zip decompression engine could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The issue is due to improper validation of zip files. An attacker could exploit this by sending an email message with a crafted zip-compressed attachment, potentially triggering a restart of the content-scanning process and causing a temporary DoS condition.
Recommendations For versions prior to 13.0, update to version 13.0 or later to resolve the issue. As a temporary workaround, consider restricting the handling of zip-compressed attachments to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00615
CVE-2020-3134

Affected Products

Cisco Asyncos
Cisco Email Security Appliance