Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9ppw-7p8w-h9g2

Опубликовано: 19 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.8

Описание

A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow emails that should have been denied to flow through an affected device.  

This vulnerability is due to improper handling of email that passes through an affected device. An attacker could exploit this vulnerability by sending a crafted email through the affected device. A successful exploit could allow the attacker to bypass email filters on the affected device.

A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow emails that should have been denied to flow through an affected device.  

This vulnerability is due to improper handling of email that passes through an affected device. An attacker could exploit this vulnerability by sending a crafted email through the affected device. A successful exploit could allow the attacker to bypass email filters on the affected device.

EPSS

Процентиль: 27%
0.00094
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 5.8
nvd
12 месяцев назад

A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow emails that should have been denied to flow through an affected device.   This vulnerability is due to improper handling of email that passes through an affected device. An attacker could exploit this vulnerability by sending a crafted email through the affected device. A successful exploit could allow the attacker to bypass email filters on the affected device.

CVSS3: 5.8
fstec
12 месяцев назад

Уязвимость системы обеспечения безопасности электронной почты Cisco Secure Email Gateway операционной системы Cisco AsyncOS, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 27%
0.00094
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-284