cbcvebase.
CVE-2020-3370
published 2020-07-16

CVE-2020-3370: A vulnerability in URL filtering of Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to bypass URL filtering…

PriorityP433medium5.8CVSS 3.1
AVNACLPRNUINSCCNILAN
EPSS
1.28%
66.7th percentile
A vulnerability in URL filtering of Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to bypass URL filtering on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted, malicious HTTP request to an affected device. A successful exploit could allow the attacker to redirect users to malicious sites.

Affected

4 ranges
VendorProductVersion rangeFixed in
ciscocisco_email_security_appliance
ciscoemail_security_appliance< 13.0.113.0.1
ciscoemail_security_appliance>= 13.5.0 < 13.5.113.5.1
ciscoemail_security_appliance_filter

CVSS provenance

nvdv3.15.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
nvdv3.04.0MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.