The uuencode inspection engine in Cisco AsyncOS on Cisco Email Security Appliance (ESA) devices 8.5 and earlier allows remote attackers to bypass intended content restrictions via a crafted e-mail attachment with uuencode encoding, aka Bug ID CSCzv54343.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/72528 | vdb entry |
http://secunia.com/advisories/62829 | third party advisory |
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0605 | vendor advisory |
http://tools.cisco.com/security/center/viewAlert.x?alertId=37384 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/100695 | vdb entry |