cisco-sa-20161207-asyncos
Cisco Security Appliances AsyncOS Software Update Server Certificate Validation Vulnerability
Medium · Updated · Cisco
3 products with CSAF evidence
A vulnerability in the update functionality of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Management Security Appliance (SMA) could allow an unauthenticated, remote attacker to impersonate the update server. The vulnerability is due to a lack of certificate validation during the HTTPS connection toward the repository from which the update manifests are retrieved. An attacker could exploit this vulnerability by performing a man-in-the-middle attack (such as DNS hijacking) and impersonating the update server. There are no workarounds that address this vulnerability.