PT-2020-1574 · Cisco · Cisco Asyncos+1
Published
2020-01-22
·
Updated
2020-01-28
·
CVE-2020-3134
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Cisco AsyncOS Software for Cisco Email Security Appliance versions prior to 13.0
Description
A vulnerability in the zip decompression engine could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The issue is due to improper validation of zip files. An attacker could exploit this by sending an email message with a crafted zip-compressed attachment, potentially triggering a restart of the content-scanning process and causing a temporary DoS condition.
Recommendations
For versions prior to 13.0, update to version 13.0 or later to resolve the issue. As a temporary workaround, consider restricting the handling of zip-compressed attachments to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Asyncos
Cisco Email Security Appliance