CVE-2021-34741 describes a denial-of-service (DoS) vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA). This flaw, stemming from insufficient input validation, allows an unauthenticated, remote attacker to exhaust CPU resources by sending a crafted email. With a CVSS score of 7.5 (High), the vulnerability is easily exploitable over the network with low attack complexity, leading to a complete denial of service for email processing. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 13.0.4CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:* | ||
13.5.3-010CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:13.5.3-010:*:*:*:*:*:*:* | ||
13.7.0-093CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:13.7.0-093:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.