4.3
CVSSv2

CVE-2016-1411

Published: 14/12/2016 Updated: 15/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A vulnerability in the update functionality of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Management Security Appliance (SMA) could allow an unauthenticated, remote malicious user to impersonate the update server. More Information: CSCul88715, CSCul94617, CSCul94627. Known Affected Releases: 7.5.2-201 7.6.3-025 8.0.1-023 8.5.0-000 8.5.0-ER1-198 7.5.2-HP2-303 7.7.0-608 7.7.5-835 8.5.1-021 8.8.0-000 7.9.1-102 8.0.0-404 8.1.1-013 8.2.0-222. Known Fixed Releases: 8.0.2-069 8.0.2-074 8.5.7-042 9.1.0-032 8.5.2-027 9.6.1-019.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco email security appliance 8.5.1-021

cisco content security management appliance 9.1.0-004

cisco email security appliance 7.6.3-025

cisco email security appliance 8.5.0-000

cisco content security management appliance 9.1.0-033

cisco web security appliance 8.8.0-000

cisco email security appliance 7.5.2-201

cisco content security management appliance 9.1.0-103

cisco web security appliance 7.7.5-835

cisco content security management appliance 9.1.0-031

cisco email security appliance 8.5.0-er1-198

cisco email security appliance 7.5.2-hp2-303

cisco content security management appliance 9.1.0

cisco web security appliance 7.7.0-608

cisco email security appliance 8.0.1-023

cisco content security management appliance 9.6.0