7.8
CVSSv2

CVE-2015-6291

Published: 06/11/2015 Updated: 07/12/2016
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Cisco AsyncOS prior to 8.5.7-043, 9.x prior to 9.1.1-023, and 9.5.x and 9.6.x prior to 9.6.0-046 on Email Security Appliance (ESA) devices mishandles malformed fields during body-contains, attachment-contains, every-attachment-contains, attachment-binary-contains, dictionary-match, and attachment-dictionary-match filtering, which allows remote malicious users to cause a denial of service (memory consumption) via a crafted attachment in an e-mail message, aka Bug ID CSCuv47151.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco email security appliance 8.0_base

cisco email security appliance 8.5_base

cisco email security appliance 8.5.6-113

cisco email security appliance 9.1.0-032

cisco email security appliance 8.5.6-073

cisco email security appliance 9.0.0

cisco email security appliance 9.0.0-461

cisco email security appliance 8.5.6-052

cisco email security appliance 9.0.0-212

cisco email security appliance 8.5.7-042

cisco email security appliance 9.6.0-042

cisco email security appliance 9.0.5-000

cisco email security appliance 8.5.6-106

cisco email security appliance 8.5.6-074

cisco email security appliance 7.7.0-000

cisco email security appliance 7.7.1-000

Vendor Advisories

A vulnerability in the email message filtering feature of Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause an ESA device to become unavailable due to a denial of service (DoS) condition The vulnerability is due to improper input validation when an email attachment contains corrupted f ...