CVE-2016-1423
published 2016-10-28CVE-2016-1423: A vulnerability in the display of email messages in the Messages in Quarantine (MIQ) view in Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow…
PriorityP428medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.54%
72.2th percentile
A vulnerability in the display of email messages in the Messages in Quarantine (MIQ) view in Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a user to click a malicious link in the MIQ view. The malicious link could be used to facilitate a cross-site scripting (XSS) or HTML injection attack. More Information: CSCuz02235. Known Affected Releases: 8.0.2-069. Known Fixed Releases: 9.1.1-038 9.7.2-047.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance_quarantine_email_rendering | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Email Security Appliance Quarantine Email Rendering Vulnerability
vendor_cisco·2016-10-26·CVSS 4.3
CVE-2016-1423 [MEDIUM] CWE-79 Cisco Email Security Appliance Quarantine Email Rendering Vulnerability
Cisco Email Security Appliance Quarantine Email Rendering Vulnerability
A vulnerability in the display of email messages in the Messages in Quarantine (MIQ) view in Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a user to click a malicious link in the MIQ view. The malicious link could be used to facilitate a cross-site scripting (XSS) or HTML injection attack.
The vulnerability is due to malformed HTML script tags in quarantined email messages. An attacker could exploit this vulnerability by sending a crafted email message to the affected device. An exploit could allow the attacker to trick a user who views the MIQ email message into clicking a malicious link.
Cisco has not released software updates that address this vuln
Cisco
Cisco Email Security Appliance Quarantine Email Rendering Vulnerability
vendor_cisco
CVE-2016-1423 Cisco Email Security Appliance Quarantine Email Rendering Vulnerability
CVE-2016-1423: Cisco Email Security Appliance Quarantine Email Rendering Vulnerability
A vulnerability in the display of email messages in the Messages in Quarantine (MIQ) view in Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a user to click a malicious link in the MIQ view. The malicious link could be used to facilitate a cross-site scripting (XSS) or HTML injection attack. The vulnerability is due to malformed HTML script tags in quarantined email messages. An attacker could exploit this vulnerability by sending a crafted email message to the affected device. An exploit could allow the attacker to trick a user who views the MIQ email message into clicking a malicious link. Cisco has not released software updates that addre
GHSA
GHSA-9rr5-hm34-qcfm: A vulnerability in the display of email messages in the Messages in Quarantine (MIQ) view in Cisco AsyncOS for Cisco Email Security Appliance (ESA) co
ghsa_unreviewed·2022-05-17
CVE-2016-1423 [MEDIUM] CWE-79 GHSA-9rr5-hm34-qcfm: A vulnerability in the display of email messages in the Messages in Quarantine (MIQ) view in Cisco AsyncOS for Cisco Email Security Appliance (ESA) co
A vulnerability in the display of email messages in the Messages in Quarantine (MIQ) view in Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a user to click a malicious link in the MIQ view. The malicious link could be used to facilitate a cross-site scripting (XSS) or HTML injection attack. More Information: CSCuz02235. Known Affected Releases: 8.0.2-069. Known Fixed Releases: 9.1.1-038 9.7.2-047.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/93912http://www.securitytracker.com/id/1037113https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161026-esa4http://www.securityfocus.com/bid/93912http://www.securitytracker.com/id/1037113https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161026-esa4
2016-10-28
Published