CVE Feed

    Dashboard / CVE / CVE-2021-34741

    CVE-2021-34741

    A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation of incoming emails. An attacker could exploit this vulnerability by sending a crafted email through Cisco ESA. A successful exploit could allow the attacker to exhaust all the available CPU resources on an affected device for an extended period of time, preventing other emails from being processed and resulting in a DoS condition.

    Published:Nov 4, 2021
    Last Modified:Nov 21, 2024
    EPS:Nov 4, 2021
    EPSS Score:0.00238
    CVSS Score:7.5

    Affected Products

    Vendor
    Cisco
    Product
    Asyncos
    Vendor
    Cisco
    Product
    M170
    Vendor
    Cisco
    Product
    M190
    Vendor
    Cisco
    Product
    M380
    Vendor
    Cisco
    Product
    M390
    Vendor
    Cisco
    Product
    M390x
    Vendor
    Cisco
    Product
    M680
    Vendor
    Cisco
    Product
    M690
    Vendor
    Cisco
    Product
    M690x
    Vendor
    Cisco
    Product
    S195
    Vendor
    Cisco
    Product
    S395
    Vendor
    Cisco
    Product
    S695

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High