Cisco AsyncOS ソフトウェアにおけるセキュリティ機能に関する脆弱性
| Title |
Cisco AsyncOS ソフトウェアにおけるセキュリティ機能に関する脆弱性
|
| Summary |
Cisco AsyncOS ソフトウェアには、セキュリティ機能に関する脆弱性が存在します。 ベンダは、本脆弱性を Bug ID CSCvf44666 として公開しています。
|
| Possible impacts |
情報を改ざんされる可能性があります。 |
| Solution |
ベンダ情報および参考情報を参照して適切な対策を実施してください。 |
| Publication Date |
Nov. 29, 2017, midnight |
| Registration Date |
Dec. 14, 2017, 4:03 p.m. |
| Last Update |
Dec. 14, 2017, 4:03 p.m. |
|
CVSS3.0 : 警告
|
| Score |
5.8
|
| Vector |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N |
|
CVSS2.0 : 警告
|
| Score |
5
|
| Vector |
AV:N/AC:L/Au:N/C:N/I:P/A:N |
Affected System
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
Change Log
| No |
Changed Details |
Date of change |
| 0 |
[2017年12月14日] 掲載 |
Feb. 17, 2018, 10:37 a.m. |
NVD Vulnerability Information
CVE-2017-12353
| Summary |
A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. The vulnerability is due to improper error handling of a malformed MIME header in an email attachment. An attacker could exploit this vulnerability by sending an email with a crafted MIME attachment. For example, a successful exploit could allow the attacker to bypass configured user filters to drop the email. The malformed MIME headers may not be RFC compliant. However, some mail clients could still allow users to access the attachment, which may not have been properly filtered by the device. Cisco Bug IDs: CSCvf44666.
|
| Publication Date |
Nov. 30, 2017, 6:29 p.m. |
| Registration Date |
Jan. 26, 2021, 1:13 p.m. |
| Last Update |
Nov. 21, 2024, 12:09 p.m. |
Affected software configurations
| Configuration1 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:cisco:asyncos:-:*:*:*:*:*:*:* |
|
|
|
|
Related information, measures and tools
Common Vulnerabilities List