Filerting bypass in Cisco AsyncOS for Cisco Email Security Appliance and Cisco AsyncOS for Secure Web Appliance - CVE-2017-3827
Published: February 15, 2017 / Updated: February 17, 2017
Vulnerability details
The vulnerability allows a remote attacker to bypass security filtering mechanisms.
The vulnerability exists due to improper error handling when processing malformed MIME header in an email attachment. A remote unauthenticated attacker can send specially crafted email with malformed MIME attachment and bypass implemented security filters.
Affected software
Cisco AsyncOS for Secure Web Appliance
How to mitigate CVE-2017-3827
Install updates from vendor's website.