Filerting bypass in Cisco AsyncOS for Cisco Email Security Appliance and Cisco AsyncOS for Secure Web Appliance - CVE-2017-3827

 

Filerting bypass in Cisco AsyncOS for Cisco Email Security Appliance and Cisco AsyncOS for Secure Web Appliance - CVE-2017-3827

Published: February 15, 2017 / Updated: February 17, 2017


Vulnerability identifier: #VU5864
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-3827
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security filtering mechanisms.

The vulnerability exists due to improper error handling when processing malformed MIME header in an email attachment. A remote unauthenticated attacker can send specially crafted email with malformed MIME attachment and bypass implemented security filters.


Affected software

Cisco AsyncOS for Cisco Email Security Appliance
Cisco AsyncOS for Secure Web Appliance

How to mitigate CVE-2017-3827

Install updates from vendor's website.



External References

Related Security Bulletins