CVE-2015-6285
published 2015-09-14CVE-2015-6285: Format string vulnerability in Cisco Email Security Appliance (ESA) 7.6.0 and 8.0.0 allows remote attackers to cause a denial of service (memory overwrite or…
PriorityP427medium6.4CVSS 2.0
AVNACLAuNCNIPAP
EPSS
1.42%
69.9th percentile
Format string vulnerability in Cisco Email Security Appliance (ESA) 7.6.0 and 8.0.0 allows remote attackers to cause a denial of service (memory overwrite or service outage) via format string specifiers in an HTTP request, aka Bug ID CSCug21497.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
vendor_cisco6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Email Security Appliance Format String Vulnerability
vendor_cisco·2015-09-09·CVSS 6.4
CVE-2015-6285 [MEDIUM] CWE-134 Cisco Email Security Appliance Format String Vulnerability
Cisco Email Security Appliance Format String Vulnerability
The Cisco Email Security Appliance (ESA) contains a vulnerability that could allow an unauthenticated, remote attacker to impact the integrity and availability of services and data on the affected device. The impact includes a partial denial of service (DoS). In addition, the attacker could override part of the memory of the affected device.
The vulnerability is due to improper validation of string input in the web application. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to impact the integrity and availability of services and data of the device, including a partial DoS condition.
Cisco has confirmed the vulnerability; howeve
GHSA
GHSA-cwqw-mv4m-vqgq: Format string vulnerability in Cisco Email Security Appliance (ESA) 7
ghsa_unreviewed·2022-05-17
CVE-2015-6285 [MEDIUM] CWE-134 GHSA-cwqw-mv4m-vqgq: Format string vulnerability in Cisco Email Security Appliance (ESA) 7
Format string vulnerability in Cisco Email Security Appliance (ESA) 7.6.0 and 8.0.0 allows remote attackers to cause a denial of service (memory overwrite or service outage) via format string specifiers in an HTTP request, aka Bug ID CSCug21497.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-09-14
Published