Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-15971

Опубликовано: 26 нояб. 2019
Источник: nvd
CVSS3: 5.8
CVSS3: 4.3
CVSS2: 4.3
EPSS Низкий

Описание

A vulnerability in the MP3 detection engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper validation of certain MP3 file types. An attacker could exploit this vulnerability by sending a crafted MP3 file through the targeted device. A successful exploit could allow the attacker to bypass configured content filters that would normally drop the email.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:cisco:email_security_appliance_firmware:*:*:*:*:*:*:*:*
Версия до 13.0 (исключая)

EPSS

Процентиль: 38%
0.0017
Низкий

5.8 Medium

CVSS3

4.3 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-20
CWE-345

Связанные уязвимости

github
больше 3 лет назад

A vulnerability in the MP3 detection engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper validation of certain MP3 file types. An attacker could exploit this vulnerability by sending a crafted MP3 file through the targeted device. A successful exploit could allow the attacker to bypass configured content filters that would normally drop the email.

CVSS3: 5.8
fstec
около 6 лет назад

Уязвимость механизма обнаружения MP3 систем обеспечения безопасности электронной почты Cisco Email Security Appliance (ESA), позволяющая нарушителю обойти настроенные фильтры содержимого и оказать воздействие на целостность защищаемой информации

EPSS

Процентиль: 38%
0.0017
Низкий

5.8 Medium

CVSS3

4.3 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-20
CWE-345