CVE-2016-6358
published 2016-10-28CVE-2016-6358: A vulnerability in local FTP to the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a partial denial of service…
PriorityP339high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
1.75%
75.3th percentile
A vulnerability in local FTP to the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition when the FTP application unexpectedly quits. More Information: CSCux68539. Known Affected Releases: 9.1.0-032 9.7.1-000. Known Fixed Releases: 9.1.1-038.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance_ftp | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Email Security Appliance FTP Denial of Service Vulnerability
vendor_cisco·2016-10-26·CVSS 5.0
CVE-2016-6358 [MEDIUM] CWE-399 Cisco Email Security Appliance FTP Denial of Service Vulnerability
Cisco Email Security Appliance FTP Denial of Service Vulnerability
A vulnerability in local FTP to the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition when the FTP application unexpectedly quits.
The vulnerability is due to improper input validation of user-supplied fields when logging in using FTP. An attacker could exploit this vulnerability by opening an FTP connection to the targeted device and crafting user-supplied parameters. An exploit could allow the attacker to cause a partial DoS condition when the FTP process unexpectedly quits. This vulnerability does not impact other user traffic.
Cisco has released software updates that address this vulnerability. There are no workarounds that addres
Cisco
Cisco Email Security Appliance FTP Denial of Service Vulnerability
vendor_cisco
CVE-2016-6358 Cisco Email Security Appliance FTP Denial of Service Vulnerability
CVE-2016-6358: Cisco Email Security Appliance FTP Denial of Service Vulnerability
A vulnerability in local FTP to the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition when the FTP application unexpectedly quits. The vulnerability is due to improper input validation of user-supplied fields when logging in using FTP. An attacker could exploit this vulnerability by opening an FTP connection to the targeted device and crafting user-supplied parameters. An exploit could allow the attacker to cause a partial DoS condition when the FTP process unexpectedly quits. This vulnerability does not impact other user traffic. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-39
GHSA
GHSA-2qcm-46qf-rxjj: A vulnerability in local FTP to the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a partial denial of
ghsa_unreviewed·2022-05-17
CVE-2016-6358 [HIGH] CWE-20 GHSA-2qcm-46qf-rxjj: A vulnerability in local FTP to the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a partial denial of
A vulnerability in local FTP to the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition when the FTP application unexpectedly quits. More Information: CSCux68539. Known Affected Releases: 9.1.0-032 9.7.1-000. Known Fixed Releases: 9.1.1-038.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/93905http://www.securitytracker.com/id/1037115https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161026-esa6http://www.securityfocus.com/bid/93905http://www.securitytracker.com/id/1037115https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161026-esa6
2016-10-28
Published