← Back

CVE-2016-6372

nvd nist
Published: Oct 28, 2016Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A vulnerability in the email message and content filtering for malformed Multipurpose Internet Mail Extensions (MIME) headers of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of the targeted device. Emails that should have been quarantined could instead be processed. Affected Products: This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for Cisco ESA and Cisco WSA on both virtual and hardware appliances that are configured with message or content filters to scan incoming email attachments. More Information: CSCuy54740, CSCuy75174. Known Affected Releases: 9.7.1-066 9.5.0-575 WSA10.0.0-000. Known Fixed Releases: 10.0.0-125 9.1.1-038 9.7.2-047.

Affected (77)

3 products
Email Security Appliance
Web Security Appliance
Web Security Appliance 8.0.5
Configuration A
77 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 8.0.1-023
Version 8.0_base
Version 8.5.0-000
Version 8.5.0-er1-198
Version 8.5.6-052
Version 8.5.6-073
Version 8.5.6-074
Version 8.5.6-106
Version 8.5.6-113
Version 8.5.7-042
Version 8.6.0-011
Version 8.6.0
Version 8.9.0
Version 8.9.1-000
Version 8.9.2-032
Version 9.0.0-212
Version 9.0.0-461
Version 9.0.0
Version 9.0.5-000
Version 9.1.0-011
Version 9.1.0-032
Version 9.1.0-101
Version 9.1.0
Version 9.1.1-000
Version 9.4.0
Version 9.4.4-000
Version 9.5.0-000
Version 9.5.0-201
Version 9.6.0-000
Version 9.6.0-042
Version 9.6.0-051
Version 9.7.0-125
Version 9.7.1-066
Version 9.9.6-026
Version 9.9_base
Cisco
Version 5.6.0-623
Version 6.0.0-000
Version 7.1.0
Version 7.1.1
Version 7.1.2
Version 7.1.3
Version 7.1.4
Version 7.5.0-000
Version 7.5.0-825
Version 7.5.1-000
Version 7.5.2-000
Version 7.5.2-hp2-303
Version 7.7.0-000
Version 7.7.0-608
Version 7.7.1-000
Version 7.7.5-835
Version 8.0.0-000
Version 8.0.5
Version 8.0.6-078
Version 8.0.6-119
Version 8.0.6
Version 8.0.7-142
Version 8.0.7
Version 8.0.8-mr-113
Version 8.5.0-497
Version 8.5.0.000
Version 8.5.1-021
Version 8.5.2-024
Version 8.5.2-027
Version 8.5.3-055
Version 8.8.0-000
Version 8.8.0-085
Version 9.0.0-193
Version 9.0_base
Version 9.1.0-000
Version 9.1.0-070
Version 9.1_base
Version 9.5.0-235
Version 9.5.0-284
Version 9.5.0-444
Version 9.5_base
Version hot_patch_1

References (8)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.