VDB

CISCO-SA-ESA-SMA-PRIVESC-9DVKFPJ8

CISCO-SA-ESA-SMA-PRIVESC-9DVKFPJ8 PUBLISHED CVSS 6.5 MEDIUM

Multiple vulnerabilities in the web UI and CLI of Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an authenticated attacker to perform injection attacks or elevate privileges. For more information about these vulnerabilities, see the Details ["#details"] section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
Cisco Secure Email
Cisco Secure Email and Web Manager

Timeline

  • Feb 15, 2023 CVE Published
  • Feb 16, 2023 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›