CVE-2015-0605: Medium severity Cisco AsyncOS vulnerability
Published Feb 7, 2015
·Updated
The uuencode inspection engine in Cisco AsyncOS on Cisco Email Security Appliance (ESA) devices 8.5 and earlier allows remote attackers to bypass intended content restrictions via a crafted e-mail attachment with uuencode encoding, aka Bug ID CSCzv54343.
Affected Software
2 affected components
Cisco AsyncOS<=8.5
Cisco Email Security Appliance Firmware
Event History
Feb 7, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0605?
CVE-2015-0605 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2015-0605?
To fix CVE-2015-0605, upgrade the Cisco Email Security Appliance to a version later than 8.5.
3
What does CVE-2015-0605 exploit?
CVE-2015-0605 exploits the uuencode inspection engine in Cisco AsyncOS, allowing attackers to bypass content restrictions.
4
Which versions are affected by CVE-2015-0605?
CVE-2015-0605 affects Cisco AsyncOS versions 8.5 and earlier.
5
Can CVE-2015-0605 impact email security?
Yes, CVE-2015-0605 can compromise email security by allowing malicious attachments to bypass security checks.