Cisco AsyncOS Security Restriction Bypass Vulnerability (CVE-2016-1461)
Cisco AsyncOS Security Restriction Bypass Vulnerability (CVE-2016-1461)
Release date:
Updated on: 2016-08-02
Affected Systems:
Cisco AsyncOS <9.7.0-125
Description:
CVE (CAN) ID: CVE-2016-1461
The Cisco AsyncOS operating system improves the security and performance of Cisco email security devices.
The email message filtering function of Cisco AsyncOS for Cisco ESA 9.7.0-125 has a security vulnerability. Unauthenticated remote attackers can exploit this vulnerability to bypass Malware detection by creating email attachments.
<* Source: Cisco
*>
Suggestion:
Vendor patch:
Cisco
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.cisco.com/c/en/us/products/security/email-security-appliance/asyncos_index.html
This article permanently updates the link address: