CVE-2016-1315: High severity cisco email security appliance firmware vulnerability
The proxy engine in Cisco Advanced Malware Protection (AMP), when used with Email Security Appliance (ESA) 9.5.0-201, 9.6.0-051, and 9.7.0-125, allows remote attackers to bypass intended content restrictions via a malformed e-mail message containing an encoded file, aka Bug ID CSCux45338.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1315?
CVE-2016-1315 has a medium severity rating, allowing remote attackers to bypass content restrictions.
How do I fix CVE-2016-1315?
To fix CVE-2016-1315, update your Cisco Email Security Appliance firmware to a version higher than the affected releases.
Which versions are vulnerable to CVE-2016-1315?
CVE-2016-1315 affects Cisco Email Security Appliance firmware versions 9.5.0-201, 9.6.0-051, and 9.7.0-125.
What kind of attack is possible with CVE-2016-1315?
CVE-2016-1315 allows attackers to execute a bypass of intended content restrictions through malformed email messages.
Who is affected by CVE-2016-1315?
Organizations using the specified versions of Cisco Email Security Appliance firmware are at risk due to CVE-2016-1315.