PT-2022-1637 · Cisco · Cisco Email Security Appliance+1
Cesare Auteri
+3
·
Published
2022-02-16
·
Updated
2023-09-22
·
CVE-2022-20653
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Email Security Appliance (ESA) versions prior to Cisco AsyncOS Software Release 13.5.4.102
Description
A vulnerability in the DNS-based Authentication of Named Entities (DANE) email verification component could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This is due to insufficient error handling in DNS name resolution by the affected software. An attacker could exploit this by sending specially formatted email messages that are processed by an affected device, causing the device to become unreachable from management interfaces or to process additional email messages for a period of time until the device recovers, resulting in a DoS condition. Continued attacks could cause the device to become completely unavailable, resulting in a persistent DoS condition.
Recommendations
For Cisco Email Security Appliance (ESA) versions prior to Cisco AsyncOS Software Release 13.5.4.102, update to Cisco AsyncOS Software Release 13.5.4.102 or later to resolve the issue. As a temporary workaround, consider configuring the Cisco ESA to send bounce messages instead of relying on downstream dependent mail servers, and verify if DANE is enabled by checking the Mail Policies > Destination Controls > Add Destination page in the web interface and ensuring the DANE Support parameter is not enabled.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Asyncos
Cisco Email Security Appliance