5
CVSSv2

CVE-2015-4184

Published: 13/06/2015 Updated: 04/01/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The anti-spam scanner on Cisco Email Security Appliance (ESA) devices 3.3.1-09, 7.5.1-gpl-022, and 8.5.6-074 allows remote malicious users to bypass intended e-mail restrictions via a malformed DNS SPF record, aka Bug IDs CSCuu35853 and CSCuu37733.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco email security appliance 3.331-09

cisco email security appliance 7.5.1-gpl-022

cisco email security appliance 8.5.6-074

Vendor Advisories

A vulnerability in the anti-spam scanner of Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the anti-spam functionality of the ESA The vulnerability is due to improper error handling of a malformed packet in the anti-spam scanner An attacker could exploit this vulnerability by send ...