Cisco Email Security Appliance RAR File Attachment Scanner Bypass Vulnerability

A vulnerability in the content filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, remote attacker to bypass content filters configured on an affected device. Email that should have been filtered could instead be forwarded by the device.

The vulnerability is due to incorrect validation of protected or encrypted email attachments that are Roshal Archive (RAR) format files. An attacker could exploit this vulnerability by sending an email message that has a crafted RAR file attachment through an affected device. A successful exploit could allow the attacker to bypass content filters that are configured to detect and act upon protected or encrypted email attachments.

There are no workarounds that address this vulnerability.

This advisory is available at the following link:
http://ift.tt/2fcZIDa A vulnerability in the content filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, remote attacker to bypass content filters configured on an affected device. Email that should have been filtered could instead be forwarded by the device.

The vulnerability is due to incorrect validation of protected or encrypted email attachments that are Roshal Archive (RAR) format files. An attacker could exploit this vulnerability by sending an email message that has a crafted RAR file attachment through an affected device. A successful exploit could allow the attacker to bypass content filters that are configured to detect and act upon protected or encrypted email attachments.

There are no workarounds that address this vulnerability.

This advisory is available at the following link:
http://ift.tt/2fcZIDa
Security Impact Rating: Medium
CVE: CVE-2016-6458

from Cisco Security Advisory http://ift.tt/2fcZIDa