Vulnslist

find the latest Cisco vulnerabilities

Cisco Email Security Appliance and Cisco Content Security Management Appliance Denial of Service Vulnerability

cisco-sa-20200219-esa-sma-dos · High · Published · Updated

A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause repeated crashes in some internal processes that are running on the affected devices, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient input validation of email attachments. An attacker could exploit this vulnerability by sending an email message with a crafted attachment through an affected device. A successful exploit could allow the attacker to cause specific processes to crash repeatedly, resulting in the complete unavailability of both the Cisco Advanced Malware Protection (AMP) and message tracking features and in severe performance degradation while processing email. After the affected processes restart, the software resumes filtering for the same attachment, causing the affected processes to crash and restart again. A successful exploit could also allow the attacker to cause a repeated DoS condition. Manual intervention may be required to recover from this situation. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200219-esa-sma-dos

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2019-1983
Cisco Bug IDsCSCvo89192, CSCvo89182
CVSS ScoreBase 7.5
Base 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), Cisco Secure Email, Cisco Secure Email and Web Manager

Related Products

Product CVE Evidence
Cisco RV Series Routers CVE-2019-1983 Cisco OpenVuln
Cisco Nexus Dashboard CVE-2019-1983 Cisco OpenVuln
Cisco Secure Email and Web Manager CVE-2019-1983 Cisco OpenVuln
Cisco Secure Email CVE-2019-1983 Cisco OpenVuln
Cisco Email Security Appliance (ESA) CVE-2019-1983 Cisco OpenVuln
Cisco Content Security Management Appliance (SMA) CVE-2019-1983 Cisco OpenVuln