CVE-2016-6356 describes a denial-of-service vulnerability in Cisco AsyncOS Software for Email Security Appliances, affecting both virtual and hardware appliances configured with email message or content filters for incoming attachments. An unauthenticated, remote attacker can exploit this flaw to prevent the device from scanning and forwarding emails. With a CVSS v3 score of 7.5 (High), the vulnerability is easily exploitable over the network with low attack complexity, leading to a complete loss of availability for email services. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), and while it has received minimal community discussion and media coverage, it is not currently listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.3.1-09CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance:3.3.1-09:*:*:*:*:*:*:* | ||
7.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance:7.1.0:*:*:*:*:*:*:* | ||
7.1.1CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance:7.1.1:*:*:*:*:*:*:* | ||
7.1.2CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance:7.1.2:*:*:*:*:*:*:* | ||
7.1.3CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance:7.1.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.