CVE Database
/

CVE-2017-3827

Back to search

CVE-2017-3827

Published: Feb 22, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. Affected Products: This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for Cisco ESA and Cisco WSA, both virtual and hardware appliances, that are configured with message or content filters to scan incoming email attachments on the ESA or services scanning content of web access on the WSA. More Information: SCvb91473, CSCvc76500. Known Affected Releases: 10.0.0-203 9.9.9-894 WSA10.0.0-233.

VendorProductVersions

n/a

Cisco AsyncOS Software for Cisco ESA and Cisco WSA

affected
Cisco AsyncOS Software for Cisco ESA and Cisco WSA

References

96239
vdb-entry
x_refsource_BID
1037831
vdb-entry
x_refsource_SECTRACK
1037832
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now