7.5

CVE-2021-34741

Cisco Email Security Appliance Denial of Service Vulnerability

A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation of incoming emails. An attacker could exploit this vulnerability by sending a crafted email through Cisco ESA. A successful exploit could allow the attacker to exhaust all the available CPU resources on an affected device for an extended period of time, preventing other emails from being processed and resulting in a DoS condition.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Asyncos Version < 13.0.4
   Cisco ≫ M170 Version -
   Cisco ≫ M190 Version -
   Cisco ≫ M380 Version -
   Cisco ≫ M390 Version -
   Cisco ≫ M390x Version -
   Cisco ≫ M680 Version -
   Cisco ≫ M690 Version -
   Cisco ≫ M690x Version -
   Cisco ≫ S195 Version -
   Cisco ≫ S395 Version -
   Cisco ≫ S695 Version -
Cisco ≫ Asyncos Version 13.5.3-010
   Cisco ≫ M170 Version -
   Cisco ≫ M190 Version -
   Cisco ≫ M380 Version -
   Cisco ≫ M390 Version -
   Cisco ≫ M390x Version -
   Cisco ≫ M680 Version -
   Cisco ≫ M690 Version -
   Cisco ≫ M690x Version -
   Cisco ≫ S195 Version -
   Cisco ≫ S395 Version -
   Cisco ≫ S695 Version -
Cisco ≫ Asyncos Version 13.7.0-093
   Cisco ≫ M170 Version -
   Cisco ≫ M190 Version -
   Cisco ≫ M380 Version -
   Cisco ≫ M390 Version -
   Cisco ≫ M390x Version -
   Cisco ≫ M680 Version -
   Cisco ≫ M690 Version -
   Cisco ≫ M690x Version -
   Cisco ≫ S195 Version -
   Cisco ≫ S395 Version -
   Cisco ≫ S695 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.25% 0.655
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
Cisco PSIRT 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-dos-JOm9ETfO
Vendor Advisory