CVE-2015-6285

Severity CVSS v4.0:
Pending analysis
Type:
CWE-134 Format String Vulnerability
Publication date:
14/09/2015
Last modified:
12/04/2025

Description

Format string vulnerability in Cisco Email Security Appliance (ESA) 7.6.0 and 8.0.0 allows remote attackers to cause a denial of service (memory overwrite or service outage) via format string specifiers in an HTTP request, aka Bug ID CSCug21497.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:cisco:email_security_appliance:7.6.0:*:*:*:*:*:*:*
cpe:2.3:h:cisco:email_security_appliance:8.0.0:*:*:*:*:*:*:*