CVE-2016-6458: Input Validation
A vulnerability in the content filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, remote attacker to bypass content filters configured on an affected device. Email that should have been filtered could instead be forwarded by the device. This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for Cisco Email Security Appliances, both virtual and hardware appliances, if the software is configured to use a content filter for email attachments that are protected or encrypted. More Information: CSCva52546. Known Affected Releases: 10.0.0-125 9.7.1-066.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6458?
CVE-2016-6458 is classified as a medium severity vulnerability.
How do I fix CVE-2016-6458?
To fix CVE-2016-6458, update the Cisco Email Security Appliance firmware to a version that addresses the vulnerability.
Which versions of Cisco Email Security Appliance are affected by CVE-2016-6458?
CVE-2016-6458 affects Cisco Email Security Appliance firmware versions 9.7.1-066, 9.7.2-046, 9.7.2-047, 9.7.2-054, 9.9.6-026, 9.9_base, 10.0.0-124, and 10.0.0-125.
Can CVE-2016-6458 be exploited remotely?
Yes, CVE-2016-6458 can be exploited by an unauthenticated remote attacker.
What impact does CVE-2016-6458 have on email filtering?
CVE-2016-6458 allows email that should have been filtered to bypass the content filtering configured on affected devices.