CVE-2019-12706 describes a vulnerability in the Sender Policy Framework (SPF) functionality of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA). This flaw allows an unauthenticated, remote attacker to bypass configured user filters due to insufficient validation of incoming SPF messages. With a CVSS score of 7.5 (HIGH), exploitation is network-based and low complexity, potentially enabling malicious content to bypass email security controls. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 13.5.0CPE matchmatch criteria | cpe:2.3:o:cisco:email_security_appliance_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.