CVE-2017-6671 describes a vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) that allows unauthenticated, remote attackers to bypass email message scanning filters, specifically the Attachment Filter. With a CVSS score of 7.5 (HIGH), this vulnerability has a low attack complexity and could lead to high integrity impact, allowing malicious content to bypass security controls. While no public exploits, Metasploit modules, or Nuclei templates are available, and there's no evidence of active exploitation, affected organizations should upgrade to fixed releases 10.0.2-020 or 9.8.1-015 to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.7.1-066CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance_firmware:9.7.1-066:*:*:*:*:*:*:* | ||
10.0.1-087CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance_firmware:10.0.1-087:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.