Cisco drops security fixes for Smart Software Manager, security appliances
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-12706 | A vulnerability in the Sender Policy Framework (SPF) functionality of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthentic A vulnerability in the Sender Policy Framework (SPF) functionality of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the configured user filters on an affected device. The vulnerability exists because the affected software insufficiently validates certain incoming SPF messages. An attacker could exploit this vulnerability by sending a custom SPF packet to an affected device. A successful exploit could allow the attacker to bypass the configured header filters, which could allow malicious content to pass through the device. NVD description · AI analysis pending | 7.5 | 1% |
| — | ||
| CVE-2019-1947 | A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause the CPU utilization to increase to 100 percent, causing a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of email messages that contain large attachments. An attacker could exploit this vulnerability by sending a malicious email message through the targeted device. A successful exploit could allow the attacker to cause a permanent DoS condition due to high CPU utilization. This vulnerability may require manual intervention to recover the ESA. NVD description · AI analysis pending | 8.6 | 2% |
| — | ||
| CVE-2019-1983 | A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security Management A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause repeated crashes in some internal processes that are running on the affected devices, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient input validation of email attachments. An attacker could exploit this vulnerability by sending an email message with a crafted attachment through an affected device. A successful exploit could allow the attacker to cause specific processes to crash repeatedly, resulting in the complete unavailability of both the Cisco Advanced Malware Protection (AMP) and message tracking features and in severe performance degradation while processing email. After the affected processes restart, the software resumes filtering for the same attachment, causing the affected processes to crash and restart again. A successful exploit could also allow the attacker to cause a repeated DoS condition. Manual intervention may be required to recover from this situation. NVD description · AI analysis pending | 5.3 | 2% |
| — | ||
| CVE-2020-3132 | A vulnerability in the email message scanning feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote A vulnerability in the email message scanning feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a temporary denial of service (DoS) condition on an affected device. The vulnerability is due to inadequate parsing mechanisms for specific email body components. An attacker could exploit this vulnerability by sending a malicious email containing a high number of shortened URLs through an affected device. A successful exploit could allow the attacker to consume processing resources, causing a DoS condition on an affected device. To successfully exploit this vulnerability, certain conditions beyond the control of the attacker must occur. NVD description · AI analysis pending | 5.9 | 2% |
| — | ||
| CVE-2020-3158 | A vulnerability in the High Availability (HA) service of Cisco Smart Software Manager On-Prem could allow an unauthenticated, remote attacker to access a sensit A vulnerability in the High Availability (HA) service of Cisco Smart Software Manager On-Prem could allow an unauthenticated, remote attacker to access a sensitive part of the system with a high-privileged account. The vulnerability is due to a system account that has a default and static password and is not under the control of the system administrator. An attacker could exploit this vulnerability by using this default account to connect to the affected system. A successful exploit could allow the attacker to obtain read and write access to system data, including the configuration of an affected device. The attacker would gain access to a sensitive portion of the system, but the attacker would not have full administrative rights to control the device. NVD description · AI analysis pending | 9.1 | 3% |
| — |
Full article346 words · extracted from helpnetsecurity.com · click to collapse
Cisco has released a new batch of security fixes for a number of its products, including its Smart Software Manager On-Prem solution and its Email Security and Content Security Management Appliances.
Only one of the fixed vulnerabilities is deemed to be critical and none is under active exploitation.
Critical Cisco security fixes
The critical flaw (CVE-2020-3158) is in the High Availability (HA) service of the Cisco Smart Software Manager On-Prem (SSM On-Prem).
“The vulnerability is due to a system account that has a default and static password and is not under the control of the system administrator. An attacker could exploit this vulnerability by using this default account to connect to the affected system,” Cisco explained.
“A successful exploit could allow the attacker to obtain read and write access to system data, including the configuration of an affected device. The attacker would gain access to a sensitive portion of the system, but the attacker would not have full administrative rights to control the device.”
Only SSM On-Prem releases earlier than 7-202001 are affected, and only if the HA feature is enabled (it’s not by default).
High-risk flaws
Cisco Email Security Appliances (ESA) and Cisco Content Security Management Appliances (SMA) sport a high-risk DOS vulnerability (CVE-2019-1983) that can be triggered by an unauthenticated, remote attacker by sending an email message with a crafted attachment through an affected device.
ESAs are additionally vulnerable to DOS through two other flaws that can be exploited via email (CVE-2019-1947 and CVE-2020-3132) and a filter bypass flaw that can be triggered by sending a custom SPF packet to an affected device (CVE-2019-12706).
Additional high-risk vulnerabilities have been fixed in:
- Cisco Unified Contact Center (privilege escalation)
- Cisco Data Center Network Manager (privilege escalation and cross-site request forgery)
- Multiple Cisco UCS-based products – Firepower Management Center, Secure Network Server appliances, Threat Grid appliances (UEFI secure boot bypass)
All the other security advisories can be found on Cisco’s dedicated page, which should be regularly visited by administrators of Cisco equipment.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2020/02/21/cisco-security-fixes/