CVE-2009-0054
PXE Encryption in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers…
Does this matter?
Lower severity and a low EPSS score (0.79%). Track it; it rarely justifies an emergency change on its own.
Description
PXE Encryption in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to capture credentials by tricking a user into reading a modified or crafted e-mail message.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 0.79% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- cisco/ironport encryption appliance · cisco/ironport postx
- Source
- psirt@cisco.com
References
- http://osvdb.org/51396
- http://secunia.com/advisories/33479
- http://securitytracker.com/id?1021593
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080a5c4f7.shtmlVendor Advisory
- http://www.securityfocus.com/bid/33268
- http://www.vupen.com/english/advisories/2009/0140
- http://osvdb.org/51396
- http://secunia.com/advisories/33479
- http://securitytracker.com/id?1021593
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080a5c4f7.shtmlVendor Advisory
- http://www.securityfocus.com/bid/33268
- http://www.vupen.com/english/advisories/2009/0140
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.