Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-3827


A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. Affected Products: This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for Cisco ESA and Cisco WSA, both virtual and hardware appliances, that are configured with message or content filters to scan incoming email attachments on the ESA or services scanning content of web access on the WSA. More Information: SCvb91473, CSCvc76500. Known Affected Releases: 10.0.0-203 9.9.9-894 WSA10.0.0-233.


Published

2017-02-22T02:59:00.230

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 5.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco web_security_appliance 10.0.0-082 Yes
Application cisco web_security_appliance 10.0.0-124 Yes
Application cisco web_security_appliance 10.0.0-125 Yes
Application cisco web_security_appliance 10.0.0-203 Yes
Application cisco web_security_appliance 10.0.0-232 Yes
Operating System cisco email_security_appliance_firmware 9.9.6-026 Yes
Operating System cisco email_security_appliance_firmware 9.9.9-894 Yes
Operating System cisco email_security_appliance_firmware 10.0.0-082 Yes
Operating System cisco email_security_appliance_firmware 10.0.0-124 Yes
Operating System cisco email_security_appliance_firmware 10.0.0-125 Yes
Operating System cisco email_security_appliance_firmware 10.0.0-203 Yes
Operating System cisco email_security_appliance_firmware 10.0.0-232 Yes

References