CVE-2019-12635
published 2019-09-05CVE-2019-12635: A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software could allow an authenticated, remote attacker to gain…
PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
1.02%
59.6th percentile
A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software could allow an authenticated, remote attacker to gain out-of-scope access to email. The vulnerability exists because the affected software does not correctly implement role permission controls. An attacker could exploit this vulnerability by using a custom role with specific permissions. A successful exploit could allow the attacker to access the spam quarantine of other users.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_content_security_management_appliance | >= unspecified < 12.5.0 | 12.5.0 |
| cisco | content_security_management_appliance | < 12.5.0 | 12.5.0 |
| cisco | content_security_management_appliance_and_cisco_email_security_appliance | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h6wq-6w3g-434q: A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software could allow an authenticated, remote attacke
ghsa_unreviewed·2022-05-24
CVE-2019-12635 [MEDIUM] GHSA-h6wq-6w3g-434q: A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software could allow an authenticated, remote attacke
A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software could allow an authenticated, remote attacker to gain out-of-scope access to email. The vulnerability exists because the affected software does not correctly implement role permission controls. An attacker could exploit this vulnerability by using a custom role with specific permissions. A successful exploit could allow the attacker to access the spam quarantine of other users.
Cisco
Cisco Content Security Management Appliance and Cisco Email Security Appliance Information Disclosure Vulnerability
vendor_cisco·2019-09-04·CVSS 4.3
CVE-2019-12635 [MEDIUM] CWE-285 Cisco Content Security Management Appliance and Cisco Email Security Appliance Information Disclosure Vulnerability
Cisco Content Security Management Appliance and Cisco Email Security Appliance Information Disclosure Vulnerability
A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software and Cisco Email Security Appliance (ESA) could allow an authenticated, remote attacker to gain out-of-scope access to email.
The vulnerability exists because the affected software does not correctly implement role permission controls. An attacker could exploit this vulnerability by using a custom role with specific permissions. A successful exploit could allow the attacker to access the spam quarantine of other users.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available
Cisco
Cisco Content Security Management Appliance and Cisco Email Security Appliance Information Disclosure Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-12635 Cisco Content Security Management Appliance and Cisco Email Security Appliance Information Disclosure Vulnerability
CVE-2019-12635: Cisco Content Security Management Appliance and Cisco Email Security Appliance Information Disclosure Vulnerability
A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software and Cisco Email Security Appliance (ESA) could allow an authenticated, remote attacker to gain out-of-scope access to email. The vulnerability exists because the affected software does not correctly implement role permission controls. An attacker could exploit this vulnerability by using a custom role with specific permissions. A successful exploit could allow the attacker to access the spam quarantine of other users. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-285, CWE-285
Bug IDs: CSCvp62827, CSCvs
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-09-05
Published