Cisco Releases Security Update for Cisco AsyncOS Software for Cisco Email Security Appliance
Scheduled update addresses denial-of-service vulnerability in the DNS-based Authentication of Named Entities (DANE) email verification component of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA)
Summary
Scheduled update addresses denial-of-service vulnerability in the DNS-based Authentication of Named Entities (DANE) email verification component of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA)
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Cisco has released a security update to address an important vulnerability in the DNS-based Authentication of Named Entities (DANE) email verification component of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA). An unauthenticated, remote attacker could cause a denial-of-service (DOS) condition and take control of an affected system.
Remediation advice
Affected organisations are encouraged to review Cisco Security Advisories and apply the necessary update below.
Remediation steps
| Type | Step |
|---|---|
| Patch |
Cisco Email Security Appliance DNS Verification Denial of Service Vulnerability - cisco-sa-esa-dos-MxZvGtgU https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-dos-MxZvGtgU |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 18 February 2022 1:26 pm