Severity
5.8MEDIUM
EPSS
0.2%
top 56.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 26
Latest updateMay 17

Description

A vulnerability in the content scanning engine of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured message or content filters on the device. Affected Products: This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for Cisco Email Security Appliances, both virtual and hardware appliances, if the software is configured to apply a message filter or content filter to inco

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDcisco/email_security_appliance9.7.1-066, 9.7.1-hp2-207, 9.8.5-085+2
CVEListV5cisco_asyncosCisco AsyncOS

🔴Vulnerability Details

2
GHSA
GHSA-79x7-9p27-9hg6: A vulnerability in the content scanning engine of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, rem2022-05-17
CVEList
CVE-2017-3800: A vulnerability in the content scanning engine of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, rem2017-01-26

📋Vendor Advisories

6
Cisco
Cisco Aironet 1800, 2800, and 3800 Series Access Points MAC Authentication Bypass Vulnerability2017-11-01
Cisco
Cisco Aironet 1560, 2800, and 3800 Series Access Point Platforms 802.11 Denial of Service Vulnerability2017-11-01
Cisco
Cisco Aironet 1560, 2800, and 3800 Series Access Point Platforms Extensible Authentication Protocol Denial of Service Vulnerability2017-11-01
Cisco
Cisco Aironet 3800 Series Access Points Protected Management Frames User Denial of Service Vulnerability2017-11-01
Cisco
Cisco Aironet 1800, 2800, and 3800 Series Access Points Plug-and-Play Arbitrary Code Execution Vulnerability2017-05-03
CVE-2017-3800 (MEDIUM CVSS 5.8) | A vulnerability in the content scan | cvebase.io