CVE-2016-1481 is a denial-of-service vulnerability in Cisco AsyncOS Software for Email Security Appliances, affecting both virtual and hardware appliances configured with specific email message filter rules. An unauthenticated, remote attacker can exploit this flaw to disrupt service. With a CVSS score of 7.5 (High), it has a low attack complexity and requires no user interaction, leading to a high impact on availability. While no public exploit code or active exploitation has been observed, it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.5.0-000CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance:8.5.0-000:*:*:*:*:*:*:* | ||
8.5.0-er1-198CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance:8.5.0-er1-198:*:*:*:*:*:*:* | ||
8.5.6-052CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance:8.5.6-052:*:*:*:*:*:*:* | ||
8.5.6-073CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance:8.5.6-073:*:*:*:*:*:*:* | ||
8.5.6-074CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance:8.5.6-074:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.