Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass content filters that are configured on an affected device. The vulnerability is due to improper handling of password-protected zip files. An attacker could exploit this vulnerability by sending a malicious file inside a crafted zip-compressed file to an affected device. A successful exploit could allow the attacker to bypass configured content filters that would normally drop the email.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Vulnerability Type
输入验证不恰当
Vulnerability Title
Cisco Email Security Appliance 输入验证错误漏洞
Vulnerability Description
Cisco Email Security Appliance(ESA)和Cisco AsyncOS都是美国思科(Cisco)公司的产品。Cisco Email Security Appliance是一个电子邮件安全设备。Cisco AsyncOS是一款应用于思科设备的操作系统。 Cisco Email Security Appliance中的 Zip Content Filter存在输入验证错误漏洞,该漏洞允许攻击者绕过限制,以提升自身特权。
CVSS Information
N/A
Vulnerability Type
N/A