First published: Fri Oct 28 2016(Updated: )
A vulnerability in local FTP to the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition when the FTP application unexpectedly quits. More Information: CSCux68539. Known Affected Releases: 9.1.0-032 9.7.1-000. Known Fixed Releases: 9.1.1-038.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Email Security Appliance Firmware | =9.7.1-066 | |
Cisco Email Security Appliance Firmware | =9.7.2-046 | |
Cisco Email Security Appliance Firmware | =9.7.2-047 | |
Cisco Email Security Appliance Firmware | =9.7.2-054 | |
Cisco Email Security Appliance Firmware | =9.9.6-026 | |
Cisco Email Security Appliance Firmware | =9.9_base |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6358 is classified as a denial of service vulnerability.
To fix CVE-2016-6358, upgrade your Cisco Email Security Appliance to a version not affected by this vulnerability.
CVE-2016-6358 is caused by a flaw in the FTP application on the Cisco Email Security Appliance that can lead to unexpected application quits.
CVE-2016-6358 affects specific versions including 9.1.0-032, 9.7.1-000, and others listed in the vulnerability details.
Yes, CVE-2016-6358 can be exploited by an unauthenticated remote attacker.