Security restrictions bypass in Cisco Email Security Appliance - CVE-2016-6458
Published: November 2, 2016 / Updated: April 5, 2018
Vulnerability identifier: #VU1142
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6458
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated user to bypass security controls on the target system.
The weakness is due to improper input validation. By sending an email message containing a specially crafted RAR archive, a remote attacker can bypass the configured email attachment content filters.
Successful exploitation of the vulnerability results in security bypass and access to data on the vulnerable system.
The weakness is due to improper input validation. By sending an email message containing a specially crafted RAR archive, a remote attacker can bypass the configured email attachment content filters.
Successful exploitation of the vulnerability results in security bypass and access to data on the vulnerable system.
Affected software
Cisco Email Security Appliance
How to mitigate CVE-2016-6458
Install update from vendor's website.