CVE-2015-4236

CWE-3994 documents4 sources
Severity
4.3MEDIUM
EPSS
0.6%
top 30.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 10
Latest updateMay 14

Description

Cisco AsyncOS on Email Security Appliance (ESA) devices with software 8.5.6-073, 8.5.6-074, and 9.0.0-461, when clustering is enabled, allows remote attackers to cause a denial of service (clustering and SSH outage) via a packet flood, aka Bug IDs CSCur13704 and CSCuq05636.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-gh4h-fj72-jqq3: Cisco AsyncOS on Email Security Appliance (ESA) devices with software 82022-05-14
CVEList
CVE-2015-4236: Cisco AsyncOS on Email Security Appliance (ESA) devices with software 82015-07-10

📋Vendor Advisories

1
Cisco
Cisco AsyncOS for Cisco Email Security Appliance and Cisco Web Security Appliance Cluster Denial of Service Vulnerability2015-07-10
CVE-2015-4236 (MEDIUM CVSS 4.3) | Cisco AsyncOS on Email Security App | cvebase.io