← Back

CVE-2015-6291

nvd nist
Published: Nov 6, 2015Modified: May 6, 2026

JSON object

Loading...
7.8
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:C
Exploitability: 10.0 / Impact: 6.9
Source: NVD

Description

Cisco AsyncOS before 8.5.7-043, 9.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-046 on Email Security Appliance (ESA) devices mishandles malformed fields during body-contains, attachment-contains, every-attachment-contains, attachment-binary-contains, dictionary-match, and attachment-dictionary-match filtering, which allows remote attackers to cause a denial of service (memory consumption) via a crafted attachment in an e-mail message, aka Bug ID CSCuv47151.

Affected (16)

1 product
Email Security Appliance
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 7.7.0-000
Version 7.7.1-000
Version 8.0_base
Version 8.5.6-052
Version 8.5.6-073
Version 8.5.6-074
Version 8.5.6-106
Version 8.5.6-113
Version 8.5.7-042
Version 8.5_base
Version 9.0.0-212
Version 9.0.0-461
Version 9.0.0
Version 9.0.5-000
Version 9.1.0-032
Version 9.6.0-042

References (4)

Timeline

No history available yet.