CVE-2015-4278

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
16/07/2015
Last modified:
12/04/2025

Description

Cisco Email Security Appliance (ESA) devices with software 8.5.6-106 and 9.5.0-201 allow remote attackers to cause a denial of service (per-domain e-mail reception outage) by placing malformed DMARC policy data in DNS TXT records for a domain, aka Bug ID CSCuv14806.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:cisco:email_security_appliance_firmware:8.5.6-106:*:*:*:*:*:*:*
cpe:2.3:o:cisco:email_security_appliance_firmware:9.5.0-201:*:*:*:*:*:*:*