CVE-2016-1486 describes a denial-of-service vulnerability in the Cisco Email Security Appliance's Advanced Malware Protection (AMP) feature, affecting AsyncOS Software releases 9.7.1 and later when configured to scan email attachments. An unauthenticated, remote attacker can exploit this flaw to prevent the device from scanning and forwarding email messages. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network with low attack complexity, leading to a complete loss of availability. While there is no known public exploit code or active exploitation, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.5.0-000CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance:8.5.0-000:*:*:*:*:*:*:* | ||
8.5.0-er1-198CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance:8.5.0-er1-198:*:*:*:*:*:*:* | ||
8.5.6-052CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance:8.5.6-052:*:*:*:*:*:*:* | ||
8.5.6-073CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance:8.5.6-073:*:*:*:*:*:*:* | ||
8.5.6-074CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance:8.5.6-074:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.