CVE-2017-12215
Summary
| CVE | CVE-2017-12215 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-21 05:29:00 UTC |
| Updated | 2019-10-09 23:22:00 UTC |
| Description | A vulnerability in the email message filtering feature of Cisco AsyncOS Software for the Cisco Email Security Appliance could allow an unauthenticated, remote attacker to cause an affected device to run out of memory and stop scanning and forwarding email messages. When system memory is depleted, it can cause the filtering process to crash, resulting in a denial of service (DoS) condition on the device. This vulnerability affects software version 9.0 through the first fixed release of Cisco AsyncOS Software for Cisco Email Security Appliances, both virtual and hardware appliances, if the software is configured to apply a message filter or content filter to incoming email attachments. The vulnerability is not limited to any specific rules or actions for a message filter or content filter. Cisco Bug IDs: CSCvd29354. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Cisco | Asyncos | 9.0 | All | All | All |
| Operating System | Cisco | Asyncos | 9.1 | All | All | All |
| Operating System | Cisco | Asyncos | 9.1.2 | All | All | All |
| Operating System | Cisco | Asyncos | 9.5 | All | All | All |
| Operating System | Cisco | Asyncos | 9.6 | All | All | All |
| Operating System | Cisco | Asyncos | 9.7 | All | All | All |
| Operating System | Cisco | Asyncos | 9.8 | All | All | All |
| Operating System | Cisco | Asyncos | 9.0 | All | All | All |
| Operating System | Cisco | Asyncos | 9.1 | All | All | All |
| Operating System | Cisco | Asyncos | 9.1.2 | All | All | All |
| Operating System | Cisco | Asyncos | 9.5 | All | All | All |
| Operating System | Cisco | Asyncos | 9.6 | All | All | All |
| Operating System | Cisco | Asyncos | 9.7 | All | All | All |
| Operating System | Cisco | Asyncos | 9.8 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Email Security Appliance Attachment Processing Bug Lets Remote Users Consume Excessive Memory Resources - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Cisco Email Security Appliance Denial of Service Vulnerability | CONFIRM | tools.cisco.com | Vendor Advisory |
| Cisco AsyncOS Software CVE-2017-12215 Remote Denial of Service Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.