// For flags

CVE-2021-34741

Cisco Email Security Appliance Denial of Service Vulnerability

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation of incoming emails. An attacker could exploit this vulnerability by sending a crafted email through Cisco ESA. A successful exploit could allow the attacker to exhaust all the available CPU resources on an affected device for an extended period of time, preventing other emails from being processed and resulting in a DoS condition.

Una vulnerabilidad en el algoritmo de análisis del correo electrónico del software Cisco AsyncOS para Cisco Email Security Appliance (ESA) podría permitir a un atacante remoto no autenticado llevar a cabo un ataque de denegación de servicio (DoS) contra un dispositivo afectado. Esta vulnerabilidad es debido a que la comprobación de entrada de los correos electrónicos entrantes es insuficiente. Un atacante podría explotar esta vulnerabilidad mediante el envío de un correo electrónico diseñado mediante Cisco ESA. Una explotación con éxito podría permitir al atacante agotar todos los recursos de CPU disponibles en un dispositivo afectado durante un período prolongado de tiempo, impidiendo que otros correos electrónicos sean procesados y dando lugar a una condición de DoS

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-06-15 CVE Reserved
  • 2021-11-04 CVE Published
  • 2024-07-19 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-770: Allocation of Resources Without Limits or Throttling
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
< 13.0.4
Search vendor "Cisco" for product "Asyncos" and version " < 13.0.4"
-
Affected
in Cisco
Search vendor "Cisco"
M170
Search vendor "Cisco" for product "M170"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
< 13.0.4
Search vendor "Cisco" for product "Asyncos" and version " < 13.0.4"
-
Affected
in Cisco
Search vendor "Cisco"
M190
Search vendor "Cisco" for product "M190"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
< 13.0.4
Search vendor "Cisco" for product "Asyncos" and version " < 13.0.4"
-
Affected
in Cisco
Search vendor "Cisco"
M380
Search vendor "Cisco" for product "M380"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
< 13.0.4
Search vendor "Cisco" for product "Asyncos" and version " < 13.0.4"
-
Affected
in Cisco
Search vendor "Cisco"
M390
Search vendor "Cisco" for product "M390"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
< 13.0.4
Search vendor "Cisco" for product "Asyncos" and version " < 13.0.4"
-
Affected
in Cisco
Search vendor "Cisco"
M390x
Search vendor "Cisco" for product "M390x"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
< 13.0.4
Search vendor "Cisco" for product "Asyncos" and version " < 13.0.4"
-
Affected
in Cisco
Search vendor "Cisco"
M680
Search vendor "Cisco" for product "M680"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
< 13.0.4
Search vendor "Cisco" for product "Asyncos" and version " < 13.0.4"
-
Affected
in Cisco
Search vendor "Cisco"
M690
Search vendor "Cisco" for product "M690"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
< 13.0.4
Search vendor "Cisco" for product "Asyncos" and version " < 13.0.4"
-
Affected
in Cisco
Search vendor "Cisco"
M690x
Search vendor "Cisco" for product "M690x"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
< 13.0.4
Search vendor "Cisco" for product "Asyncos" and version " < 13.0.4"
-
Affected
in Cisco
Search vendor "Cisco"
S195
Search vendor "Cisco" for product "S195"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
< 13.0.4
Search vendor "Cisco" for product "Asyncos" and version " < 13.0.4"
-
Affected
in Cisco
Search vendor "Cisco"
S395
Search vendor "Cisco" for product "S395"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
< 13.0.4
Search vendor "Cisco" for product "Asyncos" and version " < 13.0.4"
-
Affected
in Cisco
Search vendor "Cisco"
S695
Search vendor "Cisco" for product "S695"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
13.5.3-010
Search vendor "Cisco" for product "Asyncos" and version "13.5.3-010"
-
Affected
in Cisco
Search vendor "Cisco"
M170
Search vendor "Cisco" for product "M170"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
13.5.3-010
Search vendor "Cisco" for product "Asyncos" and version "13.5.3-010"
-
Affected
in Cisco
Search vendor "Cisco"
M190
Search vendor "Cisco" for product "M190"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
13.5.3-010
Search vendor "Cisco" for product "Asyncos" and version "13.5.3-010"
-
Affected
in Cisco
Search vendor "Cisco"
M380
Search vendor "Cisco" for product "M380"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
13.5.3-010
Search vendor "Cisco" for product "Asyncos" and version "13.5.3-010"
-
Affected
in Cisco
Search vendor "Cisco"
M390
Search vendor "Cisco" for product "M390"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
13.5.3-010
Search vendor "Cisco" for product "Asyncos" and version "13.5.3-010"
-
Affected
in Cisco
Search vendor "Cisco"
M390x
Search vendor "Cisco" for product "M390x"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
13.5.3-010
Search vendor "Cisco" for product "Asyncos" and version "13.5.3-010"
-
Affected
in Cisco
Search vendor "Cisco"
M680
Search vendor "Cisco" for product "M680"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
13.5.3-010
Search vendor "Cisco" for product "Asyncos" and version "13.5.3-010"
-
Affected
in Cisco
Search vendor "Cisco"
M690
Search vendor "Cisco" for product "M690"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
13.5.3-010
Search vendor "Cisco" for product "Asyncos" and version "13.5.3-010"
-
Affected
in Cisco
Search vendor "Cisco"
M690x
Search vendor "Cisco" for product "M690x"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
13.5.3-010
Search vendor "Cisco" for product "Asyncos" and version "13.5.3-010"
-
Affected
in Cisco
Search vendor "Cisco"
S195
Search vendor "Cisco" for product "S195"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
13.5.3-010
Search vendor "Cisco" for product "Asyncos" and version "13.5.3-010"
-
Affected
in Cisco
Search vendor "Cisco"
S395
Search vendor "Cisco" for product "S395"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
13.5.3-010
Search vendor "Cisco" for product "Asyncos" and version "13.5.3-010"
-
Affected
in Cisco
Search vendor "Cisco"
S695
Search vendor "Cisco" for product "S695"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
13.7.0-093
Search vendor "Cisco" for product "Asyncos" and version "13.7.0-093"
-
Affected
in Cisco
Search vendor "Cisco"
M170
Search vendor "Cisco" for product "M170"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
13.7.0-093
Search vendor "Cisco" for product "Asyncos" and version "13.7.0-093"
-
Affected
in Cisco
Search vendor "Cisco"
M190
Search vendor "Cisco" for product "M190"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
13.7.0-093
Search vendor "Cisco" for product "Asyncos" and version "13.7.0-093"
-
Affected
in Cisco
Search vendor "Cisco"
M380
Search vendor "Cisco" for product "M380"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
13.7.0-093
Search vendor "Cisco" for product "Asyncos" and version "13.7.0-093"
-
Affected
in Cisco
Search vendor "Cisco"
M390
Search vendor "Cisco" for product "M390"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
13.7.0-093
Search vendor "Cisco" for product "Asyncos" and version "13.7.0-093"
-
Affected
in Cisco
Search vendor "Cisco"
M390x
Search vendor "Cisco" for product "M390x"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
13.7.0-093
Search vendor "Cisco" for product "Asyncos" and version "13.7.0-093"
-
Affected
in Cisco
Search vendor "Cisco"
M680
Search vendor "Cisco" for product "M680"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
13.7.0-093
Search vendor "Cisco" for product "Asyncos" and version "13.7.0-093"
-
Affected
in Cisco
Search vendor "Cisco"
M690
Search vendor "Cisco" for product "M690"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
13.7.0-093
Search vendor "Cisco" for product "Asyncos" and version "13.7.0-093"
-
Affected
in Cisco
Search vendor "Cisco"
M690x
Search vendor "Cisco" for product "M690x"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
13.7.0-093
Search vendor "Cisco" for product "Asyncos" and version "13.7.0-093"
-
Affected
in Cisco
Search vendor "Cisco"
S195
Search vendor "Cisco" for product "S195"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
13.7.0-093
Search vendor "Cisco" for product "Asyncos" and version "13.7.0-093"
-
Affected
in Cisco
Search vendor "Cisco"
S395
Search vendor "Cisco" for product "S395"
--
Safe
Cisco
Search vendor "Cisco"
Asyncos
Search vendor "Cisco" for product "Asyncos"
13.7.0-093
Search vendor "Cisco" for product "Asyncos" and version "13.7.0-093"
-
Affected
in Cisco
Search vendor "Cisco"
S695
Search vendor "Cisco" for product "S695"
--
Safe