ZeroHour
Cisco Security Advisoriespublished ()ingested

Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities

mediumAdvisoryimportance 25
AI summary · glm-5.3-flash

Cisco released an advisory for S/MIME ciphertext decryption flaws in Secure Email that could let unauthenticated remote attackers recover plaintext via machine-in-the-middle.

Multiple vulnerabilities in the S/MIME decryption functionality of Cisco Secure Email stem from insufficient validation of message integrity. An unauthenticated remote attacker could intercept and modify traffic between email gateways using a machine-in-the-middle technique to obtain plaintext from encrypted messages. No workarounds are available; no CVE identifiers or exploitation status were included in the advisory text.

  • Affects S/MIME decryption in Cisco Secure Email gateway products
  • Requires attacker to intercept and modify gateway traffic (MITM)
  • No workarounds provided; patching via Cisco advisory is required
Full article

Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication. There are no workarounds that address these vulnerabilities. This advisory is available at the following…

This source does not provide full text. Read it at sec.cloudapps.cisco.com.