CVE-2020-26082 describes a medium-severity vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) models C170, C190, C380, C390, C680, C690, and C690X. This flaw, due to improper handling of password-protected zip files, allows an unauthenticated, remote attacker to bypass configured content filters. By sending a crafted, malicious zip file, an attacker can circumvent email security measures, potentially delivering harmful content. While the CVSS score is 5.3 (MEDIUM) with low impact on integrity and no impact on confidentiality or availability, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 13.5.2CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.