Cisco’s Email Security Appliance is affected by a high-rated vulnerability that can allow an unauthenticated remote attacker to launch a denial-of-service attack. The vulnerability occurs in the DNS-based Authentication of Named Entities, or DANE, email verification component of Cisco’s AsyncOS software used in Cisco ESA. To exploit the vulnerability, the attacker just needs to send a specially crafted email message to be processed by an affected device. The company and the U.S. Cybersecurity and Information Security Agency advise that the released patches be applied as soon as possible.”]
Source: https://www.inforisktoday.com/ciscos-email-security-appliances-at-risk-dos-attacks-a-18542

