Lucene search

K
nvd[email protected]NVD:CVE-2021-1561
HistoryAug 18, 2021 - 8:15 p.m.

CVE-2021-1561

2021-08-1820:15:06
CWE-302
CWE-287
web.nvd.nist.gov
5
cisco secure email
web manager
spam quarantine
unauthorized access
remote attacker
security controls
email messages

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:P/A:N

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

EPSS

0.001

Percentile

40.1%

A vulnerability in the spam quarantine feature of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), could allow an authenticated, remote attacker to gain unauthorized access and modify the spam quarantine settings of another user. This vulnerability exists because access to the spam quarantine feature is not properly restricted. An attacker could exploit this vulnerability by sending malicious requests to an affected system. A successful exploit could allow the attacker to modify another user’s spam quarantine settings, possibly disabling security controls or viewing email messages stored on the spam quarantine interfaces.

Affected configurations

Nvd
Node
ciscosecure_email_and_web_managerRange14.1
AND
ciscosecure_email_and_web_managerMatch-
VendorProductVersionCPE
ciscosecure_email_and_web_manager*cpe:2.3:o:cisco:secure_email_and_web_manager:*:*:*:*:*:*:*:*
ciscosecure_email_and_web_manager-cpe:2.3:h:cisco:secure_email_and_web_manager:-:*:*:*:*:*:*:*

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:P/A:N

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

EPSS

0.001

Percentile

40.1%

Related for NVD:CVE-2021-1561