VDB
CISCO-SA-ESA-SMA-PRIVESC-9DVKFPJ8
CISCO-SA-ESA-SMA-PRIVESC-9DVKFPJ8
PUBLISHED
CVSS 6.5 MEDIUM
Multiple vulnerabilities in the web UI and CLI of Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an authenticated attacker to perform injection attacks or elevate privileges. For more information about these vulnerabilities, see the Details ["#details"] section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco Secure Email | ||
| Cisco Secure Email and Web Manager |
Exploit Intelligence
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-privesc-9DVkFpJ8 (circl)
- https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html (circl)
- https://www.cisco.com/c/en/us/products/security/secure-names.html (circl)
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwd29901 (circl)
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwd29905 (circl)
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwd50043 (circl)
- https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html#ssu (circl)
- https://www.cisco.com/c/en/us/products/end-user-license-agreement.html (circl)
- https://www.cisco.com/c/en/us/support/index.html (circl)
- https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html#fixes (circl)
…and 4 more exploits
Timeline
- Feb 15, 2023 CVE Published
- Feb 16, 2023 CVE Updated
References
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-privesc-9DVkFpJ8 advisory
- https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html url
- https://www.cisco.com/c/en/us/products/security/secure-names.html url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwd29901 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwd29905 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwd50043 url
- https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html#ssu url
- https://www.cisco.com/c/en/us/products/end-user-license-agreement.html url
- https://www.cisco.com/c/en/us/support/index.html url
- https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html#fixes url
- https://www.cisco.com/go/psirt url
- https://www.cisco.com/c/en/us/support/web/tsd-cisco-worldwide-contacts.html url
- http://www.cisco.com/web/about/security/psirt/security_vulnerability_policy.html url
- https://software.cisco.com fix