CVE-2015-4236
Last modified
CVE-2015-4236 is a vulnerability of currently unknown severity. Cisco AsyncOS on Email Security Appliance (ESA) devices with software 8.5.6-073, 8.5.6-074, and 9.0.0-461, when clustering is enabled, allows remote attackers to cause a denial of service (clustering and SSH outage) via a packet flood, aka Bug IDs CSCur13704 and CSCuq05636.. EPSS estimates a 2.39% chance of exploitation in the next 30 days.
Description
Cisco AsyncOS on Email Security Appliance (ESA) devices with software 8.5.6-073, 8.5.6-074, and 9.0.0-461, when clustering is enabled, allows remote attackers to cause a denial of service (clustering and SSH outage) via a packet flood, aka Bug IDs CSCur13704 and CSCuq05636.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Email Security Appliance | 8.5.6-074 |
| Cisco | Email Security Appliance Firmware | 8.5.6-073 |
| Cisco | Email Security Appliance Firmware | 9.0.0-461 |
References
- http://www.securityfocus.com/bid/75703Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1032855Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/75703Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1032855Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-4236?
How severe is CVE-2015-4236?
How do I fix CVE-2015-4236?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-4230Memory leak in Cisco Headend System Release allows remote at…
- CVE-2015-4231The Python interpreter in Cisco NX-OS 6.2(8a) on Nexus 7000 …
- CVE-2015-4232Cisco NX-OS 6.2(10) on Nexus and MDS 9000 devices allows loc…
- CVE-2015-4233SQL injection vulnerability in Cisco Unified MeetingPlace 8.…
- CVE-2015-4234Cisco NX-OS 6.0(2) and 6.2(2) on Nexus devices has an improp…
- CVE-2015-4235Cisco Application Policy Infrastructure Controller (APIC) de…
- CVE-2015-4237The CLI parser in Cisco NX-OS 4.1(2)E1(1), 6.2(11b), 6.2(12)…
- CVE-2015-4238The SNMP implementation in Cisco Adaptive Security Appliance…
- CVE-2015-4239Cisco Adaptive Security Appliance (ASA) Software 9.3(2.243) …
- CVE-2015-4240Cisco IP Communicator 8.6(4) allows remote attackers to caus…
- CVE-2015-4241Cisco Adaptive Security Appliance (ASA) Software 9.3(2) allo…
- CVE-2015-4242Cross-site request forgery (CSRF) vulnerability in Cisco Fir…
Are you affected by CVE-2015-4236?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
