QID 317110
Date Published: 2021-11-11
QID 317110: Cisco Email Security Appliance (ESA) Denial of Service (DoS) Vulnerability (cisco-sa-esa-dos-JOm9ETfO)
A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA)
could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack against an affected device.
Affected Products
Cisco ESA if it is running a vulnerable release of Cisco AsyncOS software.
Prior to 13.0.4
From 13.5 Prior to 13.5.4-031
From 13.7 Prior to 14.0.0
QID Detection Logic (Authenticated):
The check matches Cisco ESA version retrieved using "show version" command.
A successful exploit could allow the attacker to exhaust all the available CPU resources on an affected device
for an extended period of time, preventing other emails from being processed and resulting in a DoS condition.
Customers are advised to refer to cisco-sa-esa-dos-JOm9ETfO for more information.
- cisco-sa-esa-dos-JOm9ETfO -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-dos-JOm9ETfO
CVEs related to QID 317110
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-esa-dos-JOm9ETfO |
|