CVE-2020-3134: Cisco Email Security Appliance Zip Decompression Engine Denial of Service Vulnerability
A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper validation of zip files. An attacker could exploit this vulnerability by sending an email message with a crafted zip-compressed attachment. A successful exploit could trigger a restart of the content-scanning process, causing a temporary DoS condition. This vulnerability affects Cisco AsyncOS Software for Cisco ESA releases earlier than 13.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco AsyncOS Software for Cisco Email Security Appliance (ESA)to a version that resolves this vulnerability.Fixed in 13.0
Event History
Frequently Asked Questions
What is the vulnerability ID of this security vulnerability?
The vulnerability ID is CVE-2020-3134.
What is the severity of CVE-2020-3134?
The severity of CVE-2020-3134 is medium with a CVSS score of 6.5.
What software is affected by CVE-2020-3134?
Cisco Email Security Appliance with versions up to and excluding 13.0 is affected by CVE-2020-3134.
What is the impact of CVE-2020-3134?
CVE-2020-3134 can cause a denial of service (DoS) condition on an affected device.
How can I fix CVE-2020-3134?
Cisco has released a software update to address CVE-2020-3134. Please refer to the Cisco Security Advisory for more information.