Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5v8r-9wmj-294x

Опубликовано: 04 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4

Описание

A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass the anti-malware scanner, allowing malicious archive files to be downloaded.

This vulnerability is due to improper handling of certain archive files. An attacker could exploit this vulnerability by sending a crafted archive file, which should be blocked, through an affected device. A successful exploit could allow the attacker to bypass the anti-malware scanner and download malware onto an end user workstation. The downloaded malware will not automatically execute unless the end user extracts and launches the malicious file. 

A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass the anti-malware scanner, allowing malicious archive files to be downloaded.

This vulnerability is due to improper handling of certain archive files. An attacker could exploit this vulnerability by sending a crafted archive file, which should be blocked, through an affected device. A successful exploit could allow the attacker to bypass the anti-malware scanner and download malware onto an end user workstation. The downloaded malware will not automatically execute unless the end user extracts and launches the malicious file. 

EPSS

Процентиль: 4%
0.0014
Низкий

4 Medium

CVSS3

Дефекты

CWE-494

Связанные уязвимости

CVSS3: 4
nvd
7 месяцев назад

A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass the anti-malware scanner, allowing malicious archive files to be downloaded. This vulnerability is due to improper handling of certain archive files. An attacker could exploit this vulnerability by sending a crafted archive file, which should be blocked, through an affected device. A successful exploit could allow the attacker to bypass the anti-malware scanner and download malware onto an end user workstation. The downloaded malware will not automatically execute unless the end user extracts and launches the malicious file. 

CVSS3: 4
fstec
7 месяцев назад

Уязвимость реализации механизма динамической векторизации и потоковой передачи (DVS) средства защиты Cisco Secure Web Appliance, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 4%
0.0014
Низкий

4 Medium

CVSS3

Дефекты

CWE-494