Vulnerabilities > Cisco > Email Security Appliance Firmware > 9.7.2.046

DATE CVE VULNERABILITY TITLE RISK
2019-11-26 CVE-2019-15988 Improper Input Validation vulnerability in Cisco Email Security Appliance Firmware
A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device.
network
low complexity
cisco CWE-20
5.3
2019-11-26 CVE-2019-15971 Insufficient Verification of Data Authenticity vulnerability in Cisco Email Security Appliance Firmware
A vulnerability in the MP3 detection engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device.
network
low complexity
cisco CWE-345
4.3
2019-10-02 CVE-2019-12706 Improper Input Validation vulnerability in Cisco Email Security Appliance Firmware
A vulnerability in the Sender Policy Framework (SPF) functionality of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the configured user filters on an affected device.
network
low complexity
cisco CWE-20
7.5
2016-11-19 CVE-2016-6458 Improper Input Validation vulnerability in Cisco Email Security Appliance Firmware
A vulnerability in the content filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, remote attacker to bypass content filters configured on an affected device.
network
low complexity
cisco CWE-20
7.5
2016-09-22 CVE-2016-6406 Permissions, Privileges, and Access Controls vulnerability in Cisco Email Security Appliance Firmware
Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA) devices, when Enrollment Client before 1.0.2-065 is installed, allows remote attackers to obtain root access via a connection to the testing/debugging interface, aka Bug ID CSCvb26017.
network
low complexity
cisco CWE-264
critical
9.8