Active attacks put Cisco email security gateways at root-level risk
Daily Cyber News: Active attacks put Cisco email security gateways at root-level risk
A system designed to stop malicious email can now become an attacker’s privileged foothold. Attackers have exploited a weakness affecting on-premises Cisco Secure Email Gateway appliances running AsyncOS 16.5, 16.0, and 15.5 and earlier. A crafted email can trigger the issue without any user interaction and lead to command execution with root privileges.
Key context: Root access could allow an attacker to change security policies, hide evidence, or use the gateway to reach other systems.
For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.
Topics: cybersecurity news, cybersecurity, cyber risk, firewall, vulnerability, cisco, Active, attacks, email, security.