CVE-2019-1983

Severity
5.3MEDIUM
EPSS
0.6%
top 31.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 23
Latest updateMay 24

Description

A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause repeated crashes in some internal processes that are running on the affected devices, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient input validation of email attachments. An attacker could exploit this vulnerability by sen

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

NVDcisco/email_security_appliance11.0.1-hp5-602, 11.1.0-404+1
NVDcisco/asyncos12.012.5.0-059+3

🔴Vulnerability Details

2
GHSA
GHSA-v6r4-c6r4-r649: A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security M2022-05-24
CVEList
Cisco Email Security Appliance and Cisco Content Security Management Appliance Denial of Service Vulnerability2020-09-23

📋Vendor Advisories

4
Red Hat
krb5-appl: Improper validation of object names allows malicious server to overwrite files via rcp client2021-02-02
Jenkins
Jenkins Security Advisory 2020-08-172020-08-17
Cisco
Cisco Email Security Appliance and Cisco Content Security Management Appliance Denial of Service Vulnerability2020-02-19
Red Hat
openssh: Improper validation of object names allows malicious server to overwrite files via scp client2018-11-16
CVE-2019-1983 (MEDIUM CVSS 5.3) | A vulnerability in the email messag | cvebase.io