Input validation error in Cisco AsyncOS for Cisco Email Security Appliance - CVE-2020-3368

 

Input validation error in Cisco AsyncOS for Cisco Email Security Appliance - CVE-2020-3368

Published: June 18, 2020


Vulnerability identifier: #VU29147
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3368
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass the URL reputation filters on an affected device.

The vulnerability exists due to insufficient validation of user-supplied input in the antispam protection mechanisms. A remote attacker can craft the URL in a particular way and bypass the URL reputation filters that are configured for the affected device, which could allow malicious URLs to pass through the device.


Affected software

Cisco AsyncOS for Cisco Email Security Appliance

How to mitigate CVE-2020-3368

Install updates from vendor's website.

Cisco AsyncOS for Cisco Email Security Appliance - update to 13.5.0

External References

Related Security Bulletins