CVE-2019-1983
published 2020-09-23CVE-2019-1983: A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security Management…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
1.86%
76.9th percentile
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause repeated crashes in some internal processes that are running on the affected devices, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient input validation of email attachments. An attacker could exploit this vulnerability by sending an email message with a crafted attachment through an affected device. A successful exploit could allow the attacker to cause specific processes to crash repeatedly, resulting in the complete unavailability of both the Cisco Advanced Malware Protection (AMP) and message tracking features and in severe performance degradation while processing email. After the affected processes restart, the software resumes filtering for the same attachment, causing the affected processes to crash and restart again. A successful exploit could also allow the attacker to cause a repeated DoS condition. Manual intervention may be required to recover from this situation.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asyncos | < 11.0.1-161 | 11.0.1-161 |
| cisco | asyncos | < 11.0.3-251 | 11.0.3-251 |
| cisco | asyncos | >= 12.0 < 12.5.0-059 | 12.5.0-059 |
| cisco | asyncos | 12.0 – 12.5.0-633 | — |
| cisco | cisco_email_security_appliance | — | — |
| cisco | content_security_management_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance_and_cisco_content_security_management_appliance | — | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | jenkins_weekly | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.5HIGH
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v6r4-c6r4-r649: A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security M
ghsa_unreviewed·2022-05-24
CVE-2019-1983 [HIGH] GHSA-v6r4-c6r4-r649: A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security M
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause repeated crashes in some internal processes that are running on the affected devices, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient input validation of email attachments. An attacker could exploit this vulnerability by sending an email message with a crafted attachment through an affected device. A successful exploit could allow the attacker to cause specific processes to crash repeatedly, resulting in the complete unavailability of both the Cisco Advanced Malware Protection (AMP) and message tracking features and in
Red Hat
krb5-appl: Improper validation of object names allows malicious server to overwrite files via rcp client
vendor_redhat·2021-02-02·CVSS 5.9
CVE-2019-25017 [MEDIUM] CWE-20 krb5-appl: Improper validation of object names allows malicious server to overwrite files via rcp client
krb5-appl: Improper validation of object names allows malicious server to overwrite files via rcp client
An issue was discovered in rcp in MIT krb5-appl through 1.0.3. Due to the rcp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the rcp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious rcp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the rcp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file). This issue is similar to CVE-2019-6111 and CVE-2019-7283. NOTE: MIT krb5-appl is not supported upst
Jenkins
Jenkins Security Advisory 2020-08-17
vendor_jenkins·2020-08-17·CVSS 9.4
CVE-2019-17638 [CRITICAL] Jenkins Security Advisory 2020-08-17
Title: Jenkins Security Advisory 2020-08-17
Jenkins Security Advisory 2020-08-17
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Jenkins (core)
Descriptions
Buffer corruption in bundled Jetty
SECURITY-1983
/
CVE-2019-17638
Severity (CVSS):
Critical
Description:
Jenkins bundles Winstone-Jetty, a wrapper ar
Cisco
Cisco Email Security Appliance and Cisco Content Security Management Appliance Denial of Service Vulnerability
vendor_cisco·2020-02-19·CVSS 7.5
CVE-2019-1983 [HIGH] CWE-20 Cisco Email Security Appliance and Cisco Content Security Management Appliance Denial of Service Vulnerability
Cisco Email Security Appliance and Cisco Content Security Management Appliance Denial of Service Vulnerability
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause repeated crashes in some internal processes that are running on the affected devices, resulting in a denial of service (DoS) condition.
The vulnerability is due to insufficient input validation of email attachments. An attacker could exploit this vulnerability by sending an email message with a crafted attachment through an affected device. A successful exploit could allow the attacker to cause specific processes to crash repeatedly, resulting in the
Red Hat
openssh: Improper validation of object names allows malicious server to overwrite files via scp client
vendor_redhat·2018-11-16·CVSS 5.9
CVE-2019-6111 [MEDIUM] CWE-20 openssh: Improper validation of object names allows malicious server to overwrite files via scp client
openssh: Improper validation of object names allows malicious server to overwrite files via scp client
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).
Statement: This issue affects the scp client shipped with openssh. The SSH protocol or the SSH client is not affected. For
Cisco
Cisco Email Security Appliance and Cisco Content Security Management Appliance Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1983 Cisco Email Security Appliance and Cisco Content Security Management Appliance Denial of Service Vulnerability
CVE-2019-1983: Cisco Email Security Appliance and Cisco Content Security Management Appliance Denial of Service Vulnerability
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause repeated crashes in some internal processes that are running on the affected devices, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient input validation of email attachments. An attacker could exploit this vulnerability by sending an email message with a crafted attachment through an affected device. A successful exploit could allow the attacker to cause specific processes to crash repeatedly, res
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-09-23
Published