CVE-2015-4278: Input Validation
Cisco Email Security Appliance (ESA) devices with software 8.5.6-106 and 9.5.0-201 allow remote attackers to cause a denial of service (per-domain e-mail reception outage) by placing malformed DMARC policy data in DNS TXT records for a domain, aka Bug ID CSCuv14806.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4278?
CVE-2015-4278 has a medium severity rating, as it can cause a denial of service affecting e-mail reception.
How do I fix CVE-2015-4278?
To fix CVE-2015-4278, upgrade your Cisco Email Security Appliance to a version higher than 9.5.0-201 or 8.5.6-106.
What types of attacks does CVE-2015-4278 protect against?
CVE-2015-4278 protects against denial of service attacks aimed at disrupting e-mail reception through malformed DMARC policy data.
Which Cisco Email Security Appliance versions are affected by CVE-2015-4278?
CVE-2015-4278 affects Cisco Email Security Appliance software versions 8.5.6-106 and 9.5.0-201.
Can CVE-2015-4278 be exploited remotely?
Yes, CVE-2015-4278 can be exploited remotely by attackers sending specific malformed DMARC policy data.