Vulnslist

find the latest Cisco vulnerabilities

CVE-2020-3132

A vulnerability in the email message scanning feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a temporary denial of service (DoS) condition on an affected device. The vulnerability is due to inadequate parsing mechanisms for specific email body components. An attacker could exploit this vulnerability by sending a malicious email containing a high number of shortened URLs through an affected device. A successful exploit could allow the attacker to consume processing resources, causing a DoS condition on an affected device. To successfully exploit this vulnerability, certain conditions beyond the control of the attacker must occur.

SeverityMEDIUM
CVSS5.9
CWECWE-400
KEV
Published
Modified

Related Products

Product Advisory
Cisco RV Series Routers cisco-sa-esa-shrt-dos-wM54R8qA
Cisco Nexus Dashboard cisco-sa-esa-shrt-dos-wM54R8qA
Cisco Meraki MS Series Switches cisco-sa-esa-shrt-dos-wM54R8qA
Cisco Catalyst PON Series Switches cisco-sa-esa-shrt-dos-wM54R8qA
Cisco Secure Email cisco-sa-esa-shrt-dos-wM54R8qA
Cisco Email Security Appliance (ESA) cisco-sa-esa-shrt-dos-wM54R8qA