Логотип exploitDog
bind:CVE-2019-1955
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-1955

Количество 3

Количество 3

nvd логотип

CVE-2019-1955

больше 6 лет назад

A vulnerability in the Sender Policy Framework (SPF) functionality of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. The vulnerability is due to incomplete input and validation checking mechanisms for certain SPF messages that are sent to an affected device. An attacker could exploit this vulnerability by sending a customized SPF packet to an affected device. A successful exploit could allow the attacker to bypass the header filters that are configured for the affected device, which could allow malicious content to pass through the device.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-x58p-f2fr-mr4f

больше 3 лет назад

A vulnerability in the Sender Policy Framework (SPF) functionality of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. The vulnerability is due to incomplete input and validation checking mechanisms for certain SPF messages that are sent to an affected device. An attacker could exploit this vulnerability by sending a customized SPF packet to an affected device. A successful exploit could allow the attacker to bypass the header filters that are configured for the affected device, which could allow malicious content to pass through the device.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2019-03128

больше 6 лет назад

Уязвимость компонента Sender Policy Framework (SPF) системы обеспечения безопасности электронной почты Cisco Email Security Appliance (ESA), позволяющая нарушителю обойти настроенные фильтры содержимого и оказать воздействие на целостность защищаемой информации

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-1955

A vulnerability in the Sender Policy Framework (SPF) functionality of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. The vulnerability is due to incomplete input and validation checking mechanisms for certain SPF messages that are sent to an affected device. An attacker could exploit this vulnerability by sending a customized SPF packet to an affected device. A successful exploit could allow the attacker to bypass the header filters that are configured for the affected device, which could allow malicious content to pass through the device.

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
github логотип
GHSA-x58p-f2fr-mr4f

A vulnerability in the Sender Policy Framework (SPF) functionality of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. The vulnerability is due to incomplete input and validation checking mechanisms for certain SPF messages that are sent to an affected device. An attacker could exploit this vulnerability by sending a customized SPF packet to an affected device. A successful exploit could allow the attacker to bypass the header filters that are configured for the affected device, which could allow malicious content to pass through the device.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2019-03128

Уязвимость компонента Sender Policy Framework (SPF) системы обеспечения безопасности электронной почты Cisco Email Security Appliance (ESA), позволяющая нарушителю обойти настроенные фильтры содержимого и оказать воздействие на целостность защищаемой информации

CVSS3: 5.3
0%
Низкий
больше 6 лет назад

Уязвимостей на страницу