CVE-2021-34741
A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation of incoming emails. An attacker could exploit this vulnerability by sending a crafted email through Cisco ESA. A successful exploit could allow the attacker to exhaust all the available CPU resources on an affected device for an extended period of time, preventing other emails from being processed and resulting in a DoS condition.
Published:Nov 4, 2021
Last Modified:Nov 21, 2024
EPS:Nov 4, 2021
EPSS Score:0.00238
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Cisco
Product
Asyncos
Cisco
Asyncos
Vendor
Cisco
Product
M170
Cisco
M170
Vendor
Cisco
Product
M190
Cisco
M190
Vendor
Cisco
Product
M380
Cisco
M380
Vendor
Cisco
Product
M390
Cisco
M390
Vendor
Cisco
Product
M390x
Cisco
M390x
Vendor
Cisco
Product
M680
Cisco
M680
Vendor
Cisco
Product
M690
Cisco
M690
Vendor
Cisco
Product
M690x
Cisco
M690x
Vendor
Cisco
Product
S195
Cisco
S195
Vendor
Cisco
Product
S395
Cisco
S395
Vendor
Cisco
Product
S695
Cisco
S695
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
