CVE-2015-4184
published 2015-06-13CVE-2015-4184: The anti-spam scanner on Cisco Email Security Appliance (ESA) devices 3.3.1-09, 7.5.1-gpl-022, and 8.5.6-074 allows remote attackers to bypass intended e-mail…
PriorityP431medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
3.49%
87.9th percentile
The anti-spam scanner on Cisco Email Security Appliance (ESA) devices 3.3.1-09, 7.5.1-gpl-022, and 8.5.6-074 allows remote attackers to bypass intended e-mail restrictions via a malformed DNS SPF record, aka Bug IDs CSCuu35853 and CSCuu37733.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance_anti-spam_scanner | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Email Security Appliance Anti-Spam Scanner Bypass Vulnerability
vendor_cisco·2015-06-12·CVSS 5.0
CVE-2015-4184 [MEDIUM] CWE-20 Cisco Email Security Appliance Anti-Spam Scanner Bypass Vulnerability
Cisco Email Security Appliance Anti-Spam Scanner Bypass Vulnerability
A vulnerability in the anti-spam scanner of the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the anti-spam functionality of the ESA.
The vulnerability is due to improper handling of a malformed packet in the anti-spam scanner. An attacker could exploit this vulnerability by sending a crafted DNS Sender Policy Framework (SPF) text record. An exploit could allow the attacker to bypass the anti-spam scanner and generate a malformed packet alert.
Cisco has confirmed the vulnerability; however, software updates are not available.
To exploit this vulnerability, the attacker must send a crafted DNS SPF text record to the targeted system, making exploitation more difficult i
Cisco
Cisco Email Security Appliance Anti-Spam Scanner Bypass Vulnerability
vendor_cisco·2015-06-12·CVSS 5.0
CVE-2015-4184 [MEDIUM] CWE-20 Cisco Email Security Appliance Anti-Spam Scanner Bypass Vulnerability
Cisco Email Security Appliance Anti-Spam Scanner Bypass Vulnerability
A vulnerability in the anti-spam scanner of Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the anti-spam functionality of the ESA.
The vulnerability is due to improper error handling of a malformed packet in the anti-spam scanner. An attacker could exploit this vulnerability by sending a crafted DNS Sender Policy Framework (SPF) text record. A successful exploit could allow the attacker to bypass the anti-spam scanner and generate a malformed packet alert.
Cisco has released software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps
Cisco
Cisco Email Security Appliance Anti-Spam Scanner Bypass Vulnerability
vendor_cisco
CVE-2015-4184 Cisco Email Security Appliance Anti-Spam Scanner Bypass Vulnerability
CVE-2015-4184: Cisco Email Security Appliance Anti-Spam Scanner Bypass Vulnerability
A vulnerability in the anti-spam scanner of Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the anti-spam functionality of the ESA. The vulnerability is due to improper error handling of a malformed packet in the anti-spam scanner. An attacker could exploit this vulnerability by sending a crafted DNS Sender Policy Framework (SPF) text record. A successful exploit could allow the attacker to bypass the anti-spam scanner and generate a malformed packet alert. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-20, CWE-20
Bug IDs: CSCuu35853, CSCuu37733
GHSA
GHSA-f98j-x99g-pj9q: The anti-spam scanner on Cisco Email Security Appliance (ESA) devices 3
ghsa_unreviewed·2022-05-17
CVE-2015-4184 [MEDIUM] CWE-20 GHSA-f98j-x99g-pj9q: The anti-spam scanner on Cisco Email Security Appliance (ESA) devices 3
The anti-spam scanner on Cisco Email Security Appliance (ESA) devices 3.3.1-09, 7.5.1-gpl-022, and 8.5.6-074 allows remote attackers to bypass intended e-mail restrictions via a malformed DNS SPF record, aka Bug IDs CSCuu35853 and CSCuu37733.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-06-13
Published