漏洞标题
Cisco Email Security Appliance URL过滤拒绝服务漏洞
漏洞描述信息
Cisco Email Security Appliances (ESA)的Cisco AsyncOS软件中的电子邮件消息过滤功能存在一个漏洞,未经身份验证的远程攻击者可能会利用该漏洞导致受影响设备的CPU利用率增加到100%,从而引发拒绝服务(DoS)状况。该漏洞是由于对引用了白名单URL的电子邮件消息过滤不当导致的。攻击者可能通过发送包含大量白名单URL的恶意电子邮件消息来利用此漏洞。成功的利用可能导致持续的DoS状况,迫使我方设备停止扫描和转发电子邮件消息。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
漏洞类别
N/A
漏洞标题
Cisco Email Security Appliance URL Filtering Denial of Service Vulnerability
漏洞描述信息
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to cause the CPU utilization to increase to 100 percent, causing a denial of service (DoS) condition on an affected device. The vulnerability is due to improper filtering of email messages that contain references to whitelisted URLs. An attacker could exploit this vulnerability by sending a malicious email message that contains a large number of whitelisted URLs. A successful exploit could allow the attacker to cause a sustained DoS condition that could force the affected device to stop scanning and forwarding email messages.
CVSS信息
N/A
漏洞类别
输入验证不恰当
漏洞标题
Cisco Email Security Appliance AsyncOS Software 输入验证错误漏洞
漏洞描述信息
Cisco Email Security Appliance(ESA)是美国思科(Cisco)公司的一个电子邮件安全设备。AsyncOS Software是使用在其中的操作系统。 Cisco ESA的Cisco AsyncOS Software中的电子邮件消息过滤功能存在安全漏洞,该漏洞源于程序没有正确地过滤邮件消息。远程攻击者可通过发送恶意的邮件消息(带有大量被列入白名单的URLs)利用该漏洞造成受影响的设备拒绝服务。
CVSS信息
N/A
漏洞类别
输入验证错误