CVE-2021-1534: Cisco Email Security Appliance URL Filtering Bypass Vulnerability
A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. This vulnerability is due to improper processing of URLs. An attacker could exploit this vulnerability by crafting a URL in a particular way. A successful exploit could allow the attacker to bypass the URL reputation filters that are configured for an affected device, which could allow malicious URLs to pass through the device.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-1534 vulnerability?
CVE-2021-1534 is a vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) that allows an unauthenticated, remote attacker to bypass URL reputation filters.
How does CVE-2021-1534 vulnerability occur?
CVE-2021-1534 vulnerability occurs due to improper processing of URLs in Cisco AsyncOS Software.
What is the severity level of CVE-2021-1534 vulnerability?
CVE-2021-1534 vulnerability has a severity level of 5.3 (medium).
Which Cisco products are affected by CVE-2021-1534 vulnerability?
Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) version up to 14.0.1 is affected by CVE-2021-1534 vulnerability.
How can I mitigate CVE-2021-1534 vulnerability?
To mitigate CVE-2021-1534 vulnerability, it is recommended to upgrade to a fixed software version provided by Cisco.