30
Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities
Cisco released an advisory for S/MIME ciphertext decryption flaws in Secure Email that could let unauthenticated remote attackers recover plaintext via machine-in-the-middle.
Multiple vulnerabilities in the S/MIME decryption functionality of Cisco Secure Email stem from insufficient validation of message integrity. An unauthenticated remote attacker could intercept and modify traffic between email gateways using a machine-in-the-middle technique to obtain plaintext from encrypted messages. No workarounds are available; no CVE identifiers or exploitation status were included in the advisory text.
25
30
30
30
35
30
45
45
30
SneakyChef espionage group targets government agencies with SugarGh0st and more infection techniques
45
30
30
30
30
30
30
30
35
30
30
45
30
30
30
45
30
30
30
30
30
35
35
30
30
30
30
30
30
45