cisco-sa-20160922-esa
Cisco Email Security Appliance Internal Testing Interface Vulnerability
Critical · Updated · Cisco
1 product with CSAF evidence
A vulnerability in Cisco IronPort AsyncOS for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to obtain complete control of an affected device. The vulnerability is due to the presence of a Cisco internal testing and debugging interface (intended for use during product manufacturing only) on customer-available software releases. An attacker could exploit this vulnerability by connecting to this testing and debugging interface. An exploit could allow an attacker to obtain complete control of an affected device with root-level privileges. Cisco has released software updates that address this vulnerability. A workaround that mitigates this vulnerability is available.
| Product | CVE |
|---|---|
| Cisco Email Security Appliance (ESA) | CVE-2016-6406 |