Vulnslist

find the latest Cisco vulnerabilities

Cisco Email Security Appliance Shortened URL Denial of Service Vulnerability

cisco-sa-esa-shrt-dos-wM54R8qA · Medium · Published · Updated

A vulnerability in the email message scanning feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a temporary denial of service (DoS) condition on an affected device. The vulnerability is due to inadequate parsing mechanisms for specific email body components. An attacker could exploit this vulnerability by sending a malicious email containing a high number of shortened URLs through an affected device. A successful exploit could allow the attacker to consume processing resources, causing a DoS condition on an affected device. To successfully exploit this vulnerability, certain conditions beyond the control of the attacker must occur. Cisco has released software updates that address the vulnerability described in this advisory. There is a workaround that addresses this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-shrt-dos-wM54R8qA

Workarounds

Administrators can disable email URL filtering for shortened URLs by connecting to a device through the CLI and typing the command websecurityadvancedconfig. Under Do you want to enable URL filtering for shortened URLs? type N and commit the changes. URL filtering for shortened URLs is enabled by default.

CVEsCVE-2020-3132
Cisco Bug IDsCSCvp75565
CVSS ScoreBase 6.8
Base 6.8 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco Email Security Appliance (ESA), Cisco Secure Email

Related Products

Product CVE Evidence
Cisco RV Series Routers CVE-2020-3132 Cisco OpenVuln
Cisco Nexus Dashboard CVE-2020-3132 Cisco OpenVuln
Cisco Meraki MS Series Switches CVE-2020-3132 Cisco OpenVuln
Cisco Catalyst PON Series Switches CVE-2020-3132 Cisco OpenVuln
Cisco Secure Email CVE-2020-3132 Cisco OpenVuln
Cisco Email Security Appliance (ESA) CVE-2020-3132 Cisco OpenVuln