CVE-2018-15453 is a denial-of-service vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) affecting the S/MIME Decryption and Verification or Public Key Harvesting features. An unauthenticated, remote attacker can exploit improper input validation in S/MIME-signed emails to corrupt system memory, causing the filtering process to crash and restart. This vulnerability has a CVSS score of 8.6 (High) due to its network attack vector, low attack complexity, and high impact on availability, potentially leading to a permanent DoS condition requiring manual intervention. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, indicating it is not actively exploited. However, it has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0.1-401CPE matchmatch criteria | cpe:2.3:o:cisco:email_security_appliance_firmware:11.0.1-401:*:*:*:*:*:*:* | ||
11.1.0-131CPE matchmatch criteria | cpe:2.3:o:cisco:email_security_appliance_firmware:11.1.0-131:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.