VDB

CVE-2016-1423

CVE-2016-1423 PUBLISHED CVSS 4.300000190734863 MEDIUM

A vulnerability in the display of email messages in the Messages in Quarantine (MIQ) view in Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a user to click a malicious link in the MIQ view. The malicious link could be used to facilitate a cross-site scripting (XSS) or HTML injection attack. More Information: CSCuz02235. Known Affected Releases: 8.0.2-069. Known Fixed Releases: 9.1.1-038 9.7.2-047.

EPSS 0.55% · 68.2th percentile

Risk Scores

CVSS 2.0
4.300000190734863
EPSS Score
0.55%
68.2th percentile

Affected Products

VendorProductVersions
ciscoemail_security_appliance9.0.0-212, 8.9.1-000, 8.9.2-032
n/aCisco AsyncOS 8.0.2-069Cisco AsyncOS 8.0.2-069

Timeline

  • Oct 26, 2016 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 3, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 8, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 2, 2023 EPSS Score
  • May 25, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›