7.5

CVE-2016-6372

A vulnerability in the email message and content filtering for malformed Multipurpose Internet Mail Extensions (MIME) headers of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of the targeted device. Emails that should have been quarantined could instead be processed. Affected Products: This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for Cisco ESA and Cisco WSA on both virtual and hardware appliances that are configured with message or content filters to scan incoming email attachments. More Information: CSCuy54740, CSCuy75174. Known Affected Releases: 9.7.1-066 9.5.0-575 WSA10.0.0-000. Known Fixed Releases: 10.0.0-125 9.1.1-038 9.7.2-047.

Data is provided by the National Vulnerability Database (NVD)
CiscoEmail Security Appliance Version8.0.1-023
CiscoEmail Security Appliance Version8.0_base
CiscoEmail Security Appliance Version8.5.0-000
CiscoEmail Security Appliance Version8.5.0-er1-198
CiscoEmail Security Appliance Version8.5.6-052
CiscoEmail Security Appliance Version8.5.6-073
CiscoEmail Security Appliance Version8.5.6-074
CiscoEmail Security Appliance Version8.5.6-106
CiscoEmail Security Appliance Version8.5.6-113
CiscoEmail Security Appliance Version8.5.7-042
CiscoEmail Security Appliance Version8.6.0
CiscoEmail Security Appliance Version8.6.0-011
CiscoEmail Security Appliance Version8.9.0
CiscoEmail Security Appliance Version8.9.1-000
CiscoEmail Security Appliance Version8.9.2-032
CiscoEmail Security Appliance Version9.0.0
CiscoEmail Security Appliance Version9.0.0-212
CiscoEmail Security Appliance Version9.0.0-461
CiscoEmail Security Appliance Version9.0.5-000
CiscoEmail Security Appliance Version9.1.0
CiscoEmail Security Appliance Version9.1.0-011
CiscoEmail Security Appliance Version9.1.0-032
CiscoEmail Security Appliance Version9.1.0-101
CiscoEmail Security Appliance Version9.1.1-000
CiscoEmail Security Appliance Version9.4.0
CiscoEmail Security Appliance Version9.4.4-000
CiscoEmail Security Appliance Version9.5.0-000
CiscoEmail Security Appliance Version9.5.0-201
CiscoEmail Security Appliance Version9.6.0-000
CiscoEmail Security Appliance Version9.6.0-042
CiscoEmail Security Appliance Version9.6.0-051
CiscoEmail Security Appliance Version9.7.0-125
CiscoEmail Security Appliance Version9.7.1-066
CiscoEmail Security Appliance Version9.9.6-026
CiscoEmail Security Appliance Version9.9_base
CiscoWeb Security Appliance Version5.6.0-623
CiscoWeb Security Appliance Version6.0.0-000
CiscoWeb Security Appliance Version7.1.0
CiscoWeb Security Appliance Version7.1.1
CiscoWeb Security Appliance Version7.1.2
CiscoWeb Security Appliance Version7.1.3
CiscoWeb Security Appliance Version7.1.4
CiscoWeb Security Appliance Version7.5.0-000
CiscoWeb Security Appliance Version7.5.0-825
CiscoWeb Security Appliance Version7.5.1-000
CiscoWeb Security Appliance Version7.5.2-000
CiscoWeb Security Appliance Version7.5.2-hp2-303
CiscoWeb Security Appliance Version7.7.0-000
CiscoWeb Security Appliance Version7.7.0-608
CiscoWeb Security Appliance Version7.7.1-000
CiscoWeb Security Appliance Version7.7.5-835
CiscoWeb Security Appliance Version8.0.0-000
CiscoWeb Security Appliance Version8.0.5
CiscoWeb Security Appliance Version8.0.6
CiscoWeb Security Appliance Version8.0.6-078
CiscoWeb Security Appliance Version8.0.6-119
CiscoWeb Security Appliance Version8.0.7
CiscoWeb Security Appliance Version8.0.7-142
CiscoWeb Security Appliance Version8.0.8-mr-113
CiscoWeb Security Appliance Version8.5.0-497
CiscoWeb Security Appliance Version8.5.0.000
CiscoWeb Security Appliance Version8.5.1-021
CiscoWeb Security Appliance Version8.5.2-024
CiscoWeb Security Appliance Version8.5.2-027
CiscoWeb Security Appliance Version8.5.3-055
CiscoWeb Security Appliance Version8.8.0-000
CiscoWeb Security Appliance Version8.8.0-085
CiscoWeb Security Appliance Version9.0.0-193
CiscoWeb Security Appliance Version9.0_base
CiscoWeb Security Appliance Version9.1.0-000
CiscoWeb Security Appliance Version9.1.0-070
CiscoWeb Security Appliance Version9.1_base
CiscoWeb Security Appliance Version9.5.0-235
CiscoWeb Security Appliance Version9.5.0-284
CiscoWeb Security Appliance Version9.5.0-444
CiscoWeb Security Appliance Version9.5_base
CiscoWeb Security Appliance 8.0.5 Versionhot_patch_1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.27% 0.475
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.