CVE-2015-4184
Published Jun 13, 2015
Last updated 8 years ago
Overview
- Description
- The anti-spam scanner on Cisco Email Security Appliance (ESA) devices 3.3.1-09, 7.5.1-gpl-022, and 8.5.6-074 allows remote attackers to bypass intended e-mail restrictions via a malformed DNS SPF record, aka Bug IDs CSCuu35853 and CSCuu37733.
- Source
- ykramarz@cisco.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-20
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:cisco:email_security_appliance:3.331-09:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E30A58FD-2A24-43B6-9631-8A113F9B5957" }, { "criteria": "cpe:2.3:h:cisco:email_security_appliance:7.5.1-gpl-022:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EA233BDE-A5CF-4992-9EBD-08C7181D8C11" }, { "criteria": "cpe:2.3:h:cisco:email_security_appliance:8.5.6-074:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "64626100-2E1A-4AEE-9C86-96B60BB5BFA4" } ], "operator": "OR" } ] } ]