CVE Database
/

CVE-2018-0419

Back to search

CVE-2018-0419

Published: Aug 15, 2018

Modified: Nov 26, 2024

PUBLISHED

Description

A vulnerability in certain attachment detection mechanisms of Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of an affected system. The vulnerability is due to the improper detection of content within executable (EXE) files. An attacker could exploit this vulnerability by sending a customized EXE file that is not recognized and blocked by the ESA. A successful exploit could allow an attacker to send email messages that contain malicious executable files to unsuspecting users. Cisco Bug IDs: CSCvh03786.

VendorProductVersions

Cisco Systems, Inc.

Email Security Appliance (ESA)

affected
unspecified

Weaknesses (CWE)

References

105112
vdb-entry
x_refsource_BID
1041531
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now