SB2020030510 - Resource exhaustion in Cisco AsyncOS Software for Cisco Email Security Appliances
Published: March 5, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource exhaustion (CVE-ID: CVE-2020-3181)
The vulnerability allows a remote attacker to exhaust resources on an affected device.
The vulnerability exists due to insufficient control over system memory allocation in the malware detection functionality in Cisco Advanced Malware Protection (AMP). A remote attacker can send a specially crafted email through the targeted device, cause an email attachment that contains malware to be delivered to a user and cause email processing delays.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.