Cisco IronPort Appliance Multiple Vulnerabilities
Last Update Date:
14 Nov 2012
Release Date:
12 Nov 2012
5020
Views
RISK: High Risk
TYPE: Security software and application - Security Software & Appliance
Multiple vulnerabilities have been identified in Cisco IronPort Web Security Appliance and Cisco IronPort Email Security Appliance, which can be exploited by malicious people to compromise a vulnerable device.
The vulnerabilities are caused due to a bundled vulnerable version of Sophos Engine.
Impact
- Remote Code Execution
System / Technologies affected
- Cisco IronPort Email Security Appliance 7.x
- Cisco IronPort Web Security Appliance 7.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Vulnerability Has No Patch Available
- Workarounds
Only Cisco Ironport ESA and WSA running Sophos Anti-Virus are vulnerable. Appliances running other antivirus programs are not affected. To mitigate this issue, customers can configure the Cisco Ironport appliances to use an alternate antivirus program. Cisco is providing 30-day trial licenses for McAfee Anti-Virus through Ironport Technical Support as an interim workaround. To obtain a 30-day McAfee license please contact Ironport Technical Support at
http://www.ironport.com/support/contact_support.html
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with