CVE-2023-31488

Hyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.2647), as used in Cisco IronPort Email Security Appliance Software, Cisco Secure Email Gateway, and various non-Cisco products, allow attackers to trigger a segmentation fault and execute arbitrary code via a crafted document.
References
Link Resource
https://bst.cisco.com/quickview/bug/CSCwe11003 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:cisco:ironport_email_security_appliance:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:cisco:secure_email_gateway_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:secure_email_gateway:-:*:*:*:*:*:*:*

History

03 Sep 2024, 21:35

Type Values Removed Values Added
CWE CWE-787

19 Jan 2024, 17:50

Type Values Removed Values Added
CWE NVD-CWE-noinfo
References () https://bst.cisco.com/quickview/bug/CSCwe11003 - () https://bst.cisco.com/quickview/bug/CSCwe11003 - Vendor Advisory
First Time Cisco secure Email Gateway
Cisco
Cisco ironport Email Security Appliance
Cisco secure Email Gateway Firmware
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:o:cisco:secure_email_gateway_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:secure_email_gateway:-:*:*:*:*:*:*:*
cpe:2.3:a:cisco:ironport_email_security_appliance:-:*:*:*:*:*:*:*

10 Jan 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-10 20:15

Updated : 2024-09-03 21:35


NVD link : CVE-2023-31488

Mitre link : CVE-2023-31488

CVE.ORG link : CVE-2023-31488


JSON object : View

Products Affected

cisco

  • ironport_email_security_appliance
  • secure_email_gateway_firmware
  • secure_email_gateway
CWE
NVD-CWE-noinfo CWE-787

Out-of-bounds Write