CVE-2017-6671: Input Validation
A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured filters on the device, as demonstrated by the Attachment Filter. More Information: CSCvd34632. Known Affected Releases: 10.0.1-087 9.7.1-066. Known Fixed Releases: 10.0.2-020 9.8.1-015.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6671?
CVE-2017-6671 is rated as a high severity vulnerability allowing attackers to bypass filters.
How do I fix CVE-2017-6671?
To fix CVE-2017-6671, upgrade the Cisco Email Security Appliance firmware to a version that addresses the vulnerability.
What are the affected software versions for CVE-2017-6671?
The affected software versions for CVE-2017-6671 include Cisco Email Security Appliance firmware versions 9.7.1-066 and 10.0.1-087.
Can CVE-2017-6671 be exploited remotely?
Yes, CVE-2017-6671 can be exploited by an unauthenticated remote attacker.
What type of attack does CVE-2017-6671 involve?
CVE-2017-6671 involves an attack that bypasses configured email message scanning filters.