cisco-sa-esa-url-bypass-zZtugtg3: Cisco Email Security Appliance URL Filtering Bypass Vulnerability
A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. The vulnerability is due to insufficient input validation of URLs. An attacker could exploit this vulnerability by crafting a URL in a particular way. A successful exploit could allow the attacker to bypass the URL reputation filters that are configured for the affected device, which could allow malicious URLs to pass through the device. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-url-bypass-zZtugtg3
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-esa-url-bypass-zZtugtg3?
The severity of cisco-sa-esa-url-bypass-zZtugtg3 is considered high due to its potential impact on security controls.
How do I fix cisco-sa-esa-url-bypass-zZtugtg3?
To fix cisco-sa-esa-url-bypass-zZtugtg3, ensure that your Cisco Email Security Appliance is updated to the latest version of Cisco AsyncOS.
What is the impact of cisco-sa-esa-url-bypass-zZtugtg3?
The impact of cisco-sa-esa-url-bypass-zZtugtg3 allows an unauthenticated remote attacker to bypass URL reputation filters on affected devices.
Which products are affected by cisco-sa-esa-url-bypass-zZtugtg3?
Cisco AsyncOS Software and Cisco Email Security Appliance are affected by cisco-sa-esa-url-bypass-zZtugtg3.
Is cisco-sa-esa-url-bypass-zZtugtg3 exploitable from outside the network?
Yes, cisco-sa-esa-url-bypass-zZtugtg3 is exploitable by unauthenticated remote attackers from outside the network.