CVE-2016-6458 describes a content filtering bypass vulnerability in Cisco AsyncOS Software for Email Security Appliances, impacting both virtual and hardware appliances configured with content filters for protected or encrypted email attachments. This high-severity vulnerability (CVSS 7.5) allows an unauthenticated, remote attacker to bypass configured content filters, leading to the forwarding of emails that should have been blocked. While the vulnerability has a high impact on integrity, there is no evidence of active exploitation, public exploit code, or significant community discussion, suggesting a low current threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.7.1-066CPE matchmatch criteria | cpe:2.3:o:cisco:email_security_appliance_firmware:9.7.1-066:*:*:*:*:*:*:* | ||
9.7.2-046CPE matchmatch criteria | cpe:2.3:o:cisco:email_security_appliance_firmware:9.7.2-046:*:*:*:*:*:*:* | ||
9.7.2-047CPE matchmatch criteria | cpe:2.3:o:cisco:email_security_appliance_firmware:9.7.2-047:*:*:*:*:*:*:* | ||
9.7.2-054CPE matchmatch criteria | cpe:2.3:o:cisco:email_security_appliance_firmware:9.7.2-054:*:*:*:*:*:*:* | ||
9.9.6-026CPE matchmatch criteria | cpe:2.3:o:cisco:email_security_appliance_firmware:9.9.6-026:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.