Vulnerability Bulletins

Cisco AsyncOS Software Code Execution Vulnerability


System information

   
Affected software Cisco

Description

Cisco AsyncOS Software for Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) contain a vulnerability that could allow an authenticated remote attacker to execute arbitrary code with the privileges of the root user.Cisco has released free software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.This advisory is available at the following

More info:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140319-asyncos?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20AsyncOS%20Software%20Code%20Execution%20Vulnerability&vs_k=1

Standar resources

Property Value
CVE CVE-2014-2119.

Version history

Version Comments Date
1.0 Advisory issued 2014-03-20
Ministerio de Defensa
CNI
CCN
CCN-CERT