CVE-2018-0140

Severity
6.5MEDIUM
EPSS
0.5%
top 35.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 8
Latest updateMay 13

Description

A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance could allow an authenticated, remote attacker to download any message from the spam quarantine by modifying browser string information. The vulnerability is due to a lack of verification of authenticated user accounts. An attacker could exploit this vulnerability by modifying browser strings to see messages submitted by other users to the spam quarantine within their company.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5cisco_email_security_appliance_and_cisco_content_security_management_applianceCisco Email Security Appliance and Cisco Content Security Management Appliance
NVDcisco/email_security_appliance_firmware10.0.1-087, 11.0.0-274, 9.8.0-112+2

🔴Vulnerability Details

2
GHSA
GHSA-w5x3-hp8j-7gh2: A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance could allow an authenticated,2022-05-13
CVEList
CVE-2018-0140: A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance could allow an authenticated,2018-02-08

📋Vendor Advisories

1
Cisco
Cisco Email Security Appliance and Cisco Content Security Management Appliance Spam Quarantine Vulnerability2018-02-08
CVE-2018-0140 (MEDIUM CVSS 6.5) | A vulnerability in the spam quarant | cvebase.io