PT-2020-1761 · Cisco · Cisco Asyncos+1

Published

2020-02-19

·

Updated

2020-02-27

·

CVE-2020-3132

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco Email Security Appliance (affected versions not specified)
Description The issue is related to the email message scanning feature of Cisco AsyncOS Software, which is prone to an uncontrolled consumption of resources. This could allow a remote attacker to cause a temporary denial of service (DoS) condition on an affected device. The vulnerability is due to inadequate parsing mechanisms for specific email body components, such as a high number of shortened URLs. An attacker could exploit this by sending a malicious email through an affected device, consuming processing resources and causing a DoS condition.
Recommendations To resolve the issue, update the Cisco AsyncOS Software to a version that includes the fix for this problem. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01001
CVE-2020-3132

Affected Products

Cisco Asyncos
Cisco Email Security Appliance