Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cisco Email Security Appliance GZIP Content Filter Bypass Vulnerability
Vulnerability Description
A vulnerability in the GZIP decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper validation of GZIP-formatted files. An attacker could exploit this vulnerability by sending a malicious file inside a crafted GZIP-compressed file. A successful exploit could allow the attacker to bypass configured content filters that would normally drop the email.
CVSS Information
N/A
Vulnerability Type
输入验证不恰当
Vulnerability Title
Cisco Email Security Appliance AsyncOS Software 输入验证错误漏洞
Vulnerability Description
Cisco Email Security Appliance(ESA)是美国思科(Cisco)公司的一个电子邮件安全设备。AsyncOS Software是运行在其中的一套操作系统。 Cisco ESA中的AsyncOS Software的GZIP解压引擎存在输入验证错误漏洞,该漏洞源于程序没有正确地验证GZIP格式的文件。远程攻击者可借助特制的GZIP压缩文件利用该漏洞绕过所配置的内容过滤器。
CVSS Information
N/A
Vulnerability Type
N/A