CVE-2016-6357: High severity cisco email security appliance firmware vulnerability
A vulnerability in the configured security policies, including drop email filtering, in Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass a configured drop filter by using an email with a corrupted attachment. More Information: CSCuz01651. Known Affected Releases: 10.0.9-015 9.7.1-066 9.9.6-026.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6357?
CVE-2016-6357 has been classified as a high severity vulnerability due to potential unauthorized email access.
How do I fix CVE-2016-6357?
To mitigate CVE-2016-6357, update your Cisco Email Security Appliance firmware to the latest version available.
What does CVE-2016-6357 affect?
CVE-2016-6357 affects certain versions of Cisco Email Security Appliance firmware, specifically 9.7.1-066 and 9.9.6-026.
Can CVE-2016-6357 be exploited remotely?
Yes, CVE-2016-6357 can be exploited by unauthenticated remote attackers using specially crafted emails.
What is the impact of CVE-2016-6357?
The impact of CVE-2016-6357 allows attackers to bypass email drop filters, potentially leading to malicious email delivery.