cisco web-security-appliance CVE-2017-3827 vulnerability in Cisco Products
Published on February 22, 2017

A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. Affected Products: This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for Cisco ESA and Cisco WSA, both virtual and hardware appliances, that are configured with message or content filters to scan incoming email attachments on the ESA or services scanning content of web access on the WSA. More Information: SCvb91473, CSCvc76500. Known Affected Releases: 10.0.0-203 9.9.9-894 WSA10.0.0-233.

NVD


Products Associated with CVE-2017-3827

stack.watch emails you whenever new vulnerabilities are published in Cisco Web Security Appliance or Cisco Email Security Appliance Firmware. Just hit a watch button to start following.

 
 

Exploit Probability

EPSS
0.36%
Percentile
57.75%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.