7.8

CVE-2016-6356

A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, remote attacker to cause an affected device to stop scanning and forwarding email messages due to a denial of service (DoS) condition. Affected Products: This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for Cisco Email Security Appliances, both virtual and hardware appliances, if the software is configured to apply a message filter or content filter to incoming email attachments. The vulnerability is not limited to any specific rules or actions for a message filter or content filter. More Information: CSCuz63143. Known Affected Releases: 8.5.7-042 9.7.0-125. Known Fixed Releases: 10.0.0-125 9.1.1-038 9.7.2-047.

Data is provided by the National Vulnerability Database (NVD)
CiscoEmail Security Appliance Version3.3.1-09
CiscoEmail Security Appliance Version7.1.0
CiscoEmail Security Appliance Version7.1.1
CiscoEmail Security Appliance Version7.1.2
CiscoEmail Security Appliance Version7.1.3
CiscoEmail Security Appliance Version7.1.4
CiscoEmail Security Appliance Version7.1.5
CiscoEmail Security Appliance Version7.3.0
CiscoEmail Security Appliance Version7.3.1
CiscoEmail Security Appliance Version7.3.2
CiscoEmail Security Appliance Version7.5.0
CiscoEmail Security Appliance Version7.5.1
CiscoEmail Security Appliance Version7.5.2
CiscoEmail Security Appliance Version7.5.2-201
CiscoEmail Security Appliance Version7.6.0
CiscoEmail Security Appliance Version7.6.1-000
CiscoEmail Security Appliance Version7.6.1-gpl-022
CiscoEmail Security Appliance Version7.6.2
CiscoEmail Security Appliance Version7.6.3-000
CiscoEmail Security Appliance Version7.6.3-025
CiscoEmail Security Appliance Version7.7.0-000
CiscoEmail Security Appliance Version7.7.1-000
CiscoEmail Security Appliance Version7.8.0
CiscoEmail Security Appliance Version7.8.0-311
CiscoEmail Security Appliance Version8.0.1-023
CiscoEmail Security Appliance Version8.0_base
CiscoEmail Security Appliance Version8.5.0-000
CiscoEmail Security Appliance Version8.5.0-er1-198
CiscoEmail Security Appliance Version8.5.6-052
CiscoEmail Security Appliance Version8.5.6-073
CiscoEmail Security Appliance Version8.5.6-074
CiscoEmail Security Appliance Version8.5.6-106
CiscoEmail Security Appliance Version8.5.6-113
CiscoEmail Security Appliance Version8.5.7-042
CiscoEmail Security Appliance Version8.6.0
CiscoEmail Security Appliance Version8.6.0-011
CiscoEmail Security Appliance Version8.9.0
CiscoEmail Security Appliance Version8.9.1-000
CiscoEmail Security Appliance Version8.9.2-032
CiscoEmail Security Appliance Version9.0.0
CiscoEmail Security Appliance Version9.0.0-212
CiscoEmail Security Appliance Version9.0.0-461
CiscoEmail Security Appliance Version9.0.5-000
CiscoEmail Security Appliance Version9.1.0
CiscoEmail Security Appliance Version9.1.0-011
CiscoEmail Security Appliance Version9.1.0-032
CiscoEmail Security Appliance Version9.1.0-101
CiscoEmail Security Appliance Version9.4.0
CiscoEmail Security Appliance Version9.4.4-000
CiscoEmail Security Appliance Version9.5.0-000
CiscoEmail Security Appliance Version9.5.0-201
CiscoEmail Security Appliance Version9.6.0-000
CiscoEmail Security Appliance Version9.6.0-042
CiscoEmail Security Appliance Version9.6.0-051
CiscoEmail Security Appliance Version9.7.0-125
CiscoEmail Security Appliance Version9.7.1-066
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.76% 0.71
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.