The proxy engine in Cisco Advanced Malware Protection (AMP), when used with Email Security Appliance (ESA) 9.5.0-201, 9.6.0-051, and 9.7.0-125, allows remote attackers to bypass intended content restrictions via a malformed e-mail message containing an encoded file, aka Bug ID CSCux45338.
References
Link | Resource |
---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160211-esaamp | Vendor Advisory |
http://www.securitytracker.com/id/1035008 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2016-02-11 17:59
Updated : 2017-10-13 12:53
NVD link : CVE-2016-1315
Mitre link : CVE-2016-1315
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
cisco
- email_security_appliance_firmeware