cisco-sa-20160922-esa

Cisco Email Security Appliance Internal Testing Interface Vulnerability

Critical · Updated · Cisco

1 product with CSAF evidence

A vulnerability in Cisco IronPort AsyncOS for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to obtain complete control of an affected device. The vulnerability is due to the presence of a Cisco internal testing and debugging interface (intended for use during product manufacturing only) on customer-available software releases. An attacker could exploit this vulnerability by connecting to this testing and debugging interface. An exploit could allow an attacker to obtain complete control of an affected device with root-level privileges. Cisco has released software updates that address this vulnerability. A workaround that mitigates this vulnerability is available.