Python 3.0 migration will be available starting w/ AsyncOS 14.2. 14.2 is expected Spring 2022. Please stay tuned for more information!
Python on Cisco Secure Email
The Python package used in our appliances is not a standard deployment --- just like AsyncOS is not your typical FreeBSD (a free and open-source Unix-like operating system descended from the Berkeley Software Distribution, which was based on Research Unix).
CVE-2018-1061 – This vulnerability is not affecting ESA
Filed Defects
Be sure to check out the following filed defects as well:
CSCum44746- to hide the Python version on HTTP banner, but no impact for ESA service / operations.
CSCvx65163- a general request for Python version 3 upgrade so there is no need to fix CVE relating to 2.4.6 in the future, completion timeline is 1.5 years from now.
Customer Concerns
How to address, when customer concerned, outside of the list above:
Cisco continues to fix CVE that are reported to PSIRT until Python is upgraded to v3.0
Python v3.0 on AsyncOS is planned as part of AsyncOS 15.0 release (CY2022)
@Robert Sherwin We recently just upgraded to 14.2.0-620 on our ESA. The Python 2.6 vulnerability is still showing on our scans and nothing in the release notes mentions a Python version upgrade. Can you please update this blog post?
It is now nearly the 4th quarter of 2022 and Cisco is still using an unsupported version of Python, after saying that this would be released earlier this year. Can we please be provided some communication as to the state of when this patch will be released and when Cisco will stop using EoL Python?
Getting Started
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: