cisco-sa-20161207-esa
Cisco Email Security Appliance Content Filter Bypass Vulnerability
Medium · Updated · Cisco
2 products with CSAF evidence
A vulnerability in the content filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, remote attacker to bypass user filters that are configured for an affected device. The vulnerability is due to improper filtering of certain TAR format files that are attached to email messages. An attacker could exploit this vulnerability by sending an email message that has a crafted TAR file attachment through an affected device. A successful exploit could allow the attacker to bypass user filters that are configured for the device. There are no workarounds that address this vulnerability.