#VU25478 Resource exhaustion in Cisco AsyncOS for Cisco Email Security Appliance - CVE-2020-3132
Published: February 20, 2020
Cisco AsyncOS for Cisco Email Security Appliance
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to inadequate parsing mechanisms for specific email body components in the email message scanning feature. A remote attacker can send a malicious email containing a high number of shortened URLs through an affected device, trigger resource exhaustion and perform a denial of service (DoS) attack.