Input validation error in Cisco AsyncOS for Cisco Email Security Appliance - CVE-2020-3133

 

Input validation error in Cisco AsyncOS for Cisco Email Security Appliance - CVE-2020-3133

Published: January 27, 2020


Vulnerability identifier: #VU24669
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3133
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass configured filters on the target device.

The vulnerability exists due to improper validation of incoming emails. A remote attacker can send a specially crafted email message to a recipient protected by the ESA and bypass the configured content filters, which could allow malicious content to pass through the device.


Affected software

Cisco AsyncOS for Cisco Email Security Appliance

How to mitigate CVE-2020-3133

Install updates from vendor's website.

Cisco AsyncOS for Cisco Email Security Appliance - update to 13.0

External References

Related Security Bulletins