First published: Sat Feb 07 2015(Updated: )
The uuencode inspection engine in Cisco AsyncOS on Cisco Email Security Appliance (ESA) devices 8.5 and earlier allows remote attackers to bypass intended content restrictions via a crafted e-mail attachment with uuencode encoding, aka Bug ID CSCzv54343.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco AsyncOS Software | <=8.5 | |
Cisco Email Security Appliance |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0605 has been classified as a medium severity vulnerability.
To fix CVE-2015-0605, upgrade the Cisco Email Security Appliance to a version later than 8.5.
CVE-2015-0605 exploits the uuencode inspection engine in Cisco AsyncOS, allowing attackers to bypass content restrictions.
CVE-2015-0605 affects Cisco AsyncOS versions 8.5 and earlier.
Yes, CVE-2015-0605 can compromise email security by allowing malicious attachments to bypass security checks.