CVE-2018-15460 is a denial-of-service vulnerability affecting Cisco AsyncOS Software for Cisco Email Security Appliances (ESA). An unauthenticated, remote attacker can exploit improper email message filtering, specifically regarding whitelisted URLs, to cause CPU utilization to reach 100%. This high-severity vulnerability (CVSS 8.6) requires no user interaction and can lead to a sustained DoS, preventing the ESA from processing emails. While not listed in CISA's KEV catalog and lacking public exploit code, it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.0.2-044_mdCPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:* | ||
>= 11.1.0, < 11.1.2-023_mdCPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.