Vulnslist

find the latest Cisco vulnerabilities

Cisco IronPort ESA Subject Header Length Denial of Service Vulnerability

Cisco-SA-20141223-CVE-2014-8016 · Medium · Published · Updated

A vulnerability in Subject header length processing on Cisco IronPort Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a limited denial of service (DoS) condition on an affected platform. The vulnerability occurs because the appliance does not limit the length of Subject headers sent through the appliance. An attacker could exploit this vulnerability by sending multiple crafted messages across the appliance, resulting in high CPU utilization. Continued high CPU utilization may cause a DoS condition on the platform. Cisco has confirmed the vulnerability in a security notice; however, software updates are not available. If attackers successfully cause a DoS condition on an affected device, processing of incoming email may stop, impacting internal email users.

Workarounds

Administrators are advised to contact the vendor regarding future updates and releases.

Administrators are advised to monitor affected systems.

CVEsCVE-2014-8016
Cisco Bug IDsCSCzv93864
CVSS ScoreBase 5.0
Base 5.0 AV:N/AC:L/Au:N/C:N/I:N/A:P/E:F/RL:U/RC:C
Product Names From Source
Cisco IronPort Email Security Appliance

CSAF Product Statuses

Product Status Source CVE Rows
Cisco IronPort Email Security Appliance known_affected cisco_csaf CVE-2014-8016 1

Related Products

Product CVE Evidence
Cisco IronPort Email Security Appliance CVE-2014-8016 Cisco OpenVuln