5
CVSSv2

CVE-2014-8016

Published: 19/12/2014 Updated: 19/12/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The Cisco IronPort Email Security Appliance (ESA) allows remote malicious users to cause a denial of service (CPU consumption) via long Subject headers in e-mail messages, aka Bug ID CSCzv93864.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ironport email security appliances

Vendor Advisories

A vulnerability in Subject header length processing on Cisco IronPort Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a limited denial of service (DoS) condition on an affected platform The vulnerability occurs because the appliance does not limit the length of Subject headers sent through the appliance An ...