CVE-2017-3827
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. Affected Products: This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for Cisco ESA and Cisco WSA, both virtual and hardware appliances, that are configured with message or content filters to scan incoming email attachments on the ESA or services scanning content of web access on the WSA. More Information: SCvb91473, CSCvc76500. Known Affected Releases: 10.0.0-203 9.9.9-894 WSA10.0.0-233.
Una vulnerabilidad en el escáner Multipurpose Internet Mail Extensions (MIME) de Cisco AsyncOS Software para Cisco Email Security Appliances (ESA) y Web Security Appliances (WSA) podría permitir a un atacante remoto no autenticado eludir filtros configurados por en usuario en el dispositivo. Productos Afectados: Esta vulnerabilidad afecta a todos los lanzamientos anteriores al primer lanzamiento reparado de Cisco AsyncOS Software para Cisco ESA y Cisco WSA, tanto accesorios virtuales como de hardware, que están configurados con filtros de mensajes o contenido para escanear adjuntos de emails entrantes en ESA o servicios de escaneo de contenido de acceso web en WSA. Más Información: SCvb91473, CSCvc76500. Lanzamientos Afectados Conocidos: 10.0.0-203 9.9.9-894 WSA10.0.0-233.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-12-21 CVE Reserved
- 2017-02-22 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/96239 | Vdb Entry | |
http://www.securitytracker.com/id/1037831 | Vdb Entry | |
http://www.securitytracker.com/id/1037832 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-asyncos | 2021-08-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Web Security Appliance Search vendor "Cisco" for product "Web Security Appliance" | 10.0.0-082 Search vendor "Cisco" for product "Web Security Appliance" and version "10.0.0-082" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Web Security Appliance Search vendor "Cisco" for product "Web Security Appliance" | 10.0.0-124 Search vendor "Cisco" for product "Web Security Appliance" and version "10.0.0-124" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Web Security Appliance Search vendor "Cisco" for product "Web Security Appliance" | 10.0.0-125 Search vendor "Cisco" for product "Web Security Appliance" and version "10.0.0-125" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Web Security Appliance Search vendor "Cisco" for product "Web Security Appliance" | 10.0.0-203 Search vendor "Cisco" for product "Web Security Appliance" and version "10.0.0-203" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Web Security Appliance Search vendor "Cisco" for product "Web Security Appliance" | 10.0.0-232 Search vendor "Cisco" for product "Web Security Appliance" and version "10.0.0-232" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Email Security Appliance Firmware Search vendor "Cisco" for product "Email Security Appliance Firmware" | 9.9.6-026 Search vendor "Cisco" for product "Email Security Appliance Firmware" and version "9.9.6-026" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Email Security Appliance Firmware Search vendor "Cisco" for product "Email Security Appliance Firmware" | 9.9.9-894 Search vendor "Cisco" for product "Email Security Appliance Firmware" and version "9.9.9-894" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Email Security Appliance Firmware Search vendor "Cisco" for product "Email Security Appliance Firmware" | 10.0.0-082 Search vendor "Cisco" for product "Email Security Appliance Firmware" and version "10.0.0-082" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Email Security Appliance Firmware Search vendor "Cisco" for product "Email Security Appliance Firmware" | 10.0.0-124 Search vendor "Cisco" for product "Email Security Appliance Firmware" and version "10.0.0-124" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Email Security Appliance Firmware Search vendor "Cisco" for product "Email Security Appliance Firmware" | 10.0.0-125 Search vendor "Cisco" for product "Email Security Appliance Firmware" and version "10.0.0-125" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Email Security Appliance Firmware Search vendor "Cisco" for product "Email Security Appliance Firmware" | 10.0.0-203 Search vendor "Cisco" for product "Email Security Appliance Firmware" and version "10.0.0-203" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Email Security Appliance Firmware Search vendor "Cisco" for product "Email Security Appliance Firmware" | 10.0.0-232 Search vendor "Cisco" for product "Email Security Appliance Firmware" and version "10.0.0-232" | - |
Affected
|