MEDIUM · 4.3

CVE-2015-4236

Cisco AsyncOS on Email Security Appliance (ESA) devices with software 8.5.6-073, 8.5.6-074, and 9.0.0-461, when clustering is enabled, allows remote attackers to cause a denial of service (clustering ...

Vulnerability Description

Cisco AsyncOS on Email Security Appliance (ESA) devices with software 8.5.6-073, 8.5.6-074, and 9.0.0-461, when clustering is enabled, allows remote attackers to cause a denial of service (clustering and SSH outage) via a packet flood, aka Bug IDs CSCur13704 and CSCuq05636.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
CiscoEmail Security Appliance8.5.6-074
CiscoEmail Security Appliance Firmware8.5.6-073

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-4236?

CVE-2015-4236 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cisco AsyncOS on Email Security Appliance (ESA) devices with software 8.5.6-073, 8.5.6-074, and 9.0.0-461, when clustering is enabled, allows remote attackers to cause a denial of service (clustering ...

How severe is CVE-2015-4236?

CVE-2015-4236 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-4236?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Email Security Appliance, Cisco Email Security Appliance Firmware.