Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2017-12215 Details

Description

A vulnerability in the email message filtering feature of Cisco AsyncOS Software for the Cisco Email Security Appliance could allow an unauthenticated, remote attacker to cause an affected device to run out of memory and stop scanning and forwarding email messages. When system memory is depleted, it can cause the filtering process to crash, resulting in a denial of service (DoS) condition on the device. This vulnerability affects software version 9.0 through the first fixed release of Cisco AsyncOS Software for Cisco Email Security Appliances, both virtual and hardware appliances, if the software is configured to apply a message filter or content filter to incoming email attachments. The vulnerability is not limited to any specific rules or actions for a message filter or content filter. Cisco Bug IDs: CSCvd29354.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-20Improper Input Validation[email protected]
CWE-20Improper Input Validation[email protected]

Affected Products

ProductVersions
cisco asyncos
9.0
9.1
9.1.2
9.5
9.6

CPE

  • cpe:2.3:o:cisco:asyncos:9.0:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:asyncos:9.1:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:asyncos:9.1.2:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:asyncos:9.5:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:asyncos:9.6:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:asyncos:9.7:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:asyncos:9.8:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

8 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2017-12215
NVD Published Date:
Sep 21, 2017
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2017-12215 Details - Not Deferred