445
VMScore

CVE-2016-1461

Published: 01/08/2016 Updated: 01/02/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cisco AsyncOS on Email Security Appliance (ESA) devices up to and including 9.7.0-125 allows remote malicious users to bypass malware detection via a crafted attachment in an e-mail message, aka Bug ID CSCuz14932.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco asyncos

Vendor Advisories

A vulnerability in the email message filtering feature of Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause an ESA to fail to detect and act upon a specific type of file that is attached to an email message The vulnerability is due to improper application of message filtering rules to ...