Input validation error in Cisco Email Security Appliance - CVE-2018-15460
Published: January 10, 2019
Cisco Email Security Appliance
Detailed vulnerability description
The vulnerability allows a remote attacker to cause DoS condition.
The vulnerability exists in the email message filtering feature due to improper filtering of email messages that contain references to whitelisted URLs. A remote attacker can send a malicious email message that contains a large number of whitelisted URLs, cause the CPU utilization to increase to 100 percent and force the affected device to stop scanning and forwarding email messages.