CVE-2019-1983 is a denial-of-service vulnerability in Cisco AsyncOS Software affecting Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA). It stems from insufficient input validation of email attachments, allowing an unauthenticated, remote attacker to repeatedly crash internal processes by sending a specially crafted email. This leads to the unavailability of AMP and message tracking features, severe performance degradation, and requires manual intervention to recover. The vulnerability has a CVSS score of 5.3 (MEDIUM), indicating a low attack complexity and no privileges required. While it can cause a persistent denial of service, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog. Community discussion and media coverage are minimal, suggesting limited public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.4.0-812CPE matchmatch criteria | cpe:2.3:a:cisco:content_security_management_appliance:11.4.0-812:*:*:*:*:*:*:* | ||
< 11.0.1-161CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:* | ||
>= 12.0, <= 12.5.0-633CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:* | ||
11.0.1-hp5-602CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance:11.0.1-hp5-602:*:*:*:*:*:*:* | ||
11.1.0-404CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance:11.1.0-404:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.