Impact
The flaw resides in the email parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway. The parser does not properly validate or sanitize certain email fields, allowing a crafted message to contain malicious SQL statements. When processed, these statements are executed, giving an attacker the ability to run arbitrary commands with root privileges on the operating system that hosts the gateway.
Affected Systems
Cisco Secure Email Gateway, specifically the Cisco AsyncOS Software component. No specific version information is provided in the advisory, so all deployments of the gateway are potentially affected until patched.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, and the vulnerability is listed in the CISA KEV catalog, underscoring its exploitation potential. The EPSS score of 28% suggests a significant likelihood that attackers will exploit this flaw. The attack vector is malicious email to the gateway. Successful exploitation would grant the attacker full control with root rights, potentially affecting confidentiality, integrity, and availability of the protected network.
OpenCVE Enrichment