Filerting bypass in Cisco AsyncOS for Cisco Email Security Appliance and Cisco AsyncOS for Web Security Appliances - CVE-2017-3827
Published: February 15, 2017 / Updated: February 17, 2017
Cisco AsyncOS for Cisco Email Security Appliance
Cisco AsyncOS for Web Security Appliances
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass security filtering mechanisms.
The vulnerability exists due to improper error handling when processing malformed MIME header in an email attachment. A remote unauthenticated attacker can send specially crafted email with malformed MIME attachment and bypass implemented security filters.
How to mitigate CVE-2017-3827
Install updates from vendor's website.