Lucene search

K
cveCiscoCVE-2015-4278
HistoryJul 16, 2015 - 7:59 p.m.

CVE-2015-4278

2015-07-1619:59:03
CWE-20
cisco
web.nvd.nist.gov
27
cisco
email security
esa
denial of service
vulnerability
cve-2015-4278
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

56.0%

Cisco Email Security Appliance (ESA) devices with software 8.5.6-106 and 9.5.0-201 allow remote attackers to cause a denial of service (per-domain e-mail reception outage) by placing malformed DMARC policy data in DNS TXT records for a domain, aka Bug ID CSCuv14806.

Affected configurations

Nvd
Node
ciscoemail_security_appliance_firmwareMatch8.5.6-106
OR
ciscoemail_security_appliance_firmwareMatch9.5.0-201
VendorProductVersionCPE
ciscoemail_security_appliance_firmware8.5.6-106cpe:2.3:o:cisco:email_security_appliance_firmware:8.5.6-106:*:*:*:*:*:*:*
ciscoemail_security_appliance_firmware9.5.0-201cpe:2.3:o:cisco:email_security_appliance_firmware:9.5.0-201:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

56.0%

Related for CVE-2015-4278