5
CVSSv2

CVE-2016-1315

Published: 12/02/2016 Updated: 13/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The proxy engine in Cisco Advanced Malware Protection (AMP), when used with Email Security Appliance (ESA) 9.5.0-201, 9.6.0-051, and 9.7.0-125, allows remote malicious users to bypass intended content restrictions via a malformed e-mail message containing an encoded file, aka Bug ID CSCux45338.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco email security appliance firmeware 9.5.0-201

cisco email security appliance firmeware 9.6.0-051

cisco email security appliance firmeware 9.7.0-125

cisco email security appliance firmeware 9.7.0-782

cisco email security appliance firmeware 9.1.0-032

Vendor Advisories

A vulnerability in the proxy engine of the Cisco Advanced Malware Protection (AMP) and the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass security restrictions The vulnerability is due to improper handling of malformed file methods An attacker could exploit this vulnerability by encoding files wit ...