CVE-2019-1947 is a denial-of-service vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA). It allows an unauthenticated, remote attacker to cause 100% CPU utilization by sending a malicious email with a large attachment, leading to a permanent DoS condition requiring manual intervention. With a CVSS score of 8.6 (High), this vulnerability is easily exploitable over the network with low attack complexity and no user interaction, resulting in high availability impact. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed on the KEV catalog, indicating it is not actively exploited. Community discussion and media coverage are minimal, suggesting low public attention despite its severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.1.0-131CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance:11.1.0-131:*:*:*:*:*:*:* | ||
12.1.0-085CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:12.1.0-085:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.