CVE-2017-3827
Last modified
CVE-2017-3827 is a vulnerability of currently unknown severity. A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. Affected Products: This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for Cisco ESA and Cisco WSA, both virtual and hardware appliances, that are configured with message or content filters to scan incoming email attachments on the ESA or services scanning content of web access on the WSA. EPSS estimates a 1.93% chance of exploitation in the next 30 days.
Description
A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. Affected Products: This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for Cisco ESA and Cisco WSA, both virtual and hardware appliances, that are configured with message or content filters to scan incoming email attachments on the ESA or services scanning content of web access on the WSA. More Information: SCvb91473, CSCvc76500. Known Affected Releases: 10.0.0-203 9.9.9-894 WSA10.0.0-233.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Web Security Appliance | 10.0.0-082 |
| Cisco | Web Security Appliance | 10.0.0-124 |
| Cisco | Web Security Appliance | 10.0.0-125 |
| Cisco | Web Security Appliance | 10.0.0-203 |
| Cisco | Web Security Appliance | 10.0.0-232 |
| Cisco | Email Security Appliance Firmware | 9.9.6-026 |
| Cisco | Email Security Appliance Firmware | 9.9.9-894 |
| Cisco | Email Security Appliance Firmware | 10.0.0-082 |
| Cisco | Email Security Appliance Firmware | 10.0.0-124 |
| Cisco | Email Security Appliance Firmware | 10.0.0-125 |
| Cisco | Email Security Appliance Firmware | 10.0.0-203 |
| Cisco | Email Security Appliance Firmware | 10.0.0-232 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-3827?
How severe is CVE-2017-3827?
How do I fix CVE-2017-3827?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-3821A vulnerability in the serviceability page of Cisco Unified …
- CVE-2017-3822A vulnerability in the logging subsystem of the Cisco Firepo…5.3
- CVE-2017-3823An issue was discovered in the Cisco WebEx Extension before …
- CVE-2017-3824A vulnerability in the handling of list headers in Cisco cBR…
- CVE-2017-3825A vulnerability in the ICMP ingress packet processing of Cis…
- CVE-2017-3826A vulnerability in the Stream Control Transmission Protocol …
- CVE-2017-3828A vulnerability in the web-based management interface of Cis…
- CVE-2017-3829A vulnerability in the web-based management interface of Cis…
- CVE-2017-3830A vulnerability in an internal API of the Cisco Meeting Serv…
- CVE-2017-3831A vulnerability in the web-based GUI of Cisco Mobility Expre…
- CVE-2017-3832A vulnerability in the web management interface of Cisco Wir…7.5
- CVE-2017-3833A vulnerability in the web framework of Cisco Unified Commun…
Are you affected by CVE-2017-3827?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
