CVE-2014-3381
Cisco AsyncOS < 8.5 - Malware Filtering Bypass via Crafted ZIP Archive
Title source: llmDescription
The ZIP inspection engine in Cisco AsyncOS 8.5 and earlier on the Cisco Email Security Appliance (ESA) does not properly analyze ZIP archives, which allows remote attackers to bypass malware filtering via a crafted archive, aka Bug ID CSCup07934.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
x_refsource_cisco
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3381
Vendor Advisory x_refsource_confirm
http://tools.cisco.com/security/center/viewAlert.x?alertId=36062
Scores
EPSS
0.0172
EPSS Percentile
75.1%
Details
CWE
CWE-264
Status
published
Products (1)
cisco/asyncos
< 8.5
Published
Oct 19, 2014
Tracked Since
Feb 18, 2026