CVE-2021-34741

HIGH

Cisco AsyncOS - Unauthenticated Denial of Service via Crafted Email Input

Title source: llm
STIX 2.1

Description

A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation of incoming emails. An attacker could exploit this vulnerability by sending a crafted email through Cisco ESA. A successful exploit could allow the attacker to exhaust all the available CPU resources on an affected device for an extended period of time, preventing other emails from being processed and resulting in a DoS condition.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0024
EPSS Percentile 46.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (3)
cisco/asyncos 13.5.3-010
cisco/asyncos 13.7.0-093
cisco/asyncos < 13.0.4
Published Nov 04, 2021
Tracked Since Feb 18, 2026