Lucene search

K
ciscoCiscoCISCO-SA-ESA-SMA-PRIVESC-9DVKFPJ8
HistoryFeb 15, 2023 - 4:00 p.m.

Cisco Email Security Appliance and Cisco Secure Email and Web Manager Vulnerabilities

2023-02-1516:00:00
tools.cisco.com
36
cisco
email security
web manager
vulnerabilities
injection attacks
privilege escalation
software updates

0.001 Low

EPSS

Percentile

44.4%

Multiple vulnerabilities in the web UI and CLI of Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an authenticated attacker to perform injection attacks or elevate privileges.

For more information about these vulnerabilities, see the Details [“#details”] section of this advisory.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-privesc-9DVkFpJ8 [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-privesc-9DVkFpJ8”]

Affected configurations

Vulners
Node
ciscoemail_security_applianceMatchany
OR
ciscocontent_security_management_applianceMatchany
OR
ciscoemail_security_applianceMatchany
OR
ciscocontent_security_management_applianceMatchany

0.001 Low

EPSS

Percentile

44.4%

Related for CISCO-SA-ESA-SMA-PRIVESC-9DVKFPJ8