Skip to main content

Cisco IronPort Appliance Multiple Vulnerabilities

Last Update Date: 14 Nov 2012 Release Date: 12 Nov 2012 4449 Views

RISK: High Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

Multiple vulnerabilities have been identified in Cisco IronPort Web Security Appliance and Cisco IronPort Email Security Appliance, which can be exploited by malicious people to compromise a vulnerable device.

 

The vulnerabilities are caused due to a bundled vulnerable version of Sophos Engine.


Impact

  • Remote Code Execution

System / Technologies affected

  • Cisco IronPort Email Security Appliance 7.x
  • Cisco IronPort Web Security Appliance 7.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Vulnerability Has No Patch Available
  • Workarounds
    Only Cisco Ironport ESA and WSA running Sophos Anti-Virus are vulnerable. Appliances running other antivirus programs are not affected. To mitigate this issue, customers can configure the Cisco Ironport appliances to use an alternate antivirus program. Cisco is providing 30-day trial licenses for McAfee Anti-Virus through Ironport Technical Support as an interim workaround. To obtain a 30-day McAfee license please contact Ironport Technical Support at
    http://www.ironport.com/support/contact_support.html
  •  

 


Vulnerability Identifier

  • No CVE information is available

Source


Related Link