CVE-2019-1921

MEDIUM

Cisco Email Security Appliance - Unauthenticated Content Filter Bypass via Malicious Attachment Naming

Title source: llm
STIX 2.1

Description

A vulnerability in the attachment scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper input validation of the email body. An attacker could exploit this vulnerability by naming a malicious attachment with a specific pattern. A successful exploit could allow the attacker to bypass configured content filters that would normally block the attachment.

References (1)

Core 1
Core References

Scores

CVSS v3 5.8
EPSS 0.0141
EPSS Percentile 69.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (1)
cisco/email_security_appliance 12.0.0-419
Published Jul 06, 2019
Tracked Since Feb 18, 2026