CVE-2017-3827
Last modified
CVE-2017-3827 is a vulnerability of currently unknown severity. A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. Affected Products: This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for Cisco ESA and Cisco WSA, both virtual and hardware appliances, that are configured with message or content filters to scan incoming email attachments on the ESA or services scanning content of web access on the WSA. EPSS estimates a 1.93% chance of exploitation in the next 30 days.
Description
A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. Affected Products: This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for Cisco ESA and Cisco WSA, both virtual and hardware appliances, that are configured with message or content filters to scan incoming email attachments on the ESA or services scanning content of web access on the WSA. More Information: SCvb91473, CSCvc76500. Known Affected Releases: 10.0.0-203 9.9.9-894 WSA10.0.0-233.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Web Security Appliance | 10.0.0-082 |
| Cisco | Web Security Appliance | 10.0.0-124 |
| Cisco | Web Security Appliance | 10.0.0-125 |
| Cisco | Web Security Appliance | 10.0.0-203 |
| Cisco | Web Security Appliance | 10.0.0-232 |
| Cisco | Email Security Appliance Firmware | 9.9.6-026 |
| Cisco | Email Security Appliance Firmware | 9.9.9-894 |
| Cisco | Email Security Appliance Firmware | 10.0.0-082 |
| Cisco | Email Security Appliance Firmware | 10.0.0-124 |
| Cisco | Email Security Appliance Firmware | 10.0.0-125 |
| Cisco | Email Security Appliance Firmware | 10.0.0-203 |
| Cisco | Email Security Appliance Firmware | 10.0.0-232 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-3827?
How severe is CVE-2017-3827?
How do I fix CVE-2017-3827?
Are you affected by CVE-2017-3827?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
