Cisco Asyncos vulnerabilities

49 known vulnerabilities affecting cisco/asyncos.

Total CVEs
49
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH20MEDIUM28

Vulnerabilities

Page 2 of 3
CVE-2022-20867MEDIUMCVSS 6.5≥ 13.0, < 14.2.1≥ 12.0, < 14.2.02022-11-04
CVE-2022-20867 [MEDIUM] CWE-89 CVE-2022-20867: A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct SQL injection attacks as root on an affected system. The attacker must have the credentials of a high-privileged user account. This vulnerability is due to improper
nvd
CVE-2022-20942MEDIUMCVSS 6.5fixed in 14.2.1-015≥ 14.3.0, < 14.3.0-023+5 more2022-11-04
CVE-2022-20942 [MEDIUM] CWE-359 CVE-2022-20942: A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to retrieve sensitive information from an affected device, including user credentials. T
nvd
CVE-2022-20781MEDIUMCVSS 5.4fixed in 14.52022-04-06
CVE-2022-20781 [MEDIUM] CWE-79 CVE-2022-20781: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Web Securi A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists because the web-based management interface does not p
nvd
CVE-2022-20675MEDIUMCVSS 5.3≥ 14.0, < 14.02.0-020≥ 12.5, < 14.1.0-239+1 more2022-04-06
CVE-2022-20675 [MEDIUM] CWE-248 CVE-2022-20675: A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appl A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Secure Email and Web Manager, formerly Security Management Appliance, could allow an unauthenticated, remote attacker to crash the Simple Network Management Protocol (SNMP) service, resulting in a denial of service (DoS) conditi
nvd
CVE-2022-20653HIGHCVSS 7.5fixed in 13.0.3≥ 13.5.0, < 13.5.4.102+1 more2022-02-17
CVE-2022-20653 [HIGH] CWE-399 CVE-2022-20653: A vulnerability in the DNS-based Authentication of Named Entities (DANE) email verification componen A vulnerability in the DNS-based Authentication of Named Entities (DANE) email verification component of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error handling in DNS name
nvd
CVE-2021-34741HIGHCVSS 7.5fixed in 13.0.4v13.5.3-010+1 more2021-11-04
CVE-2021-34741 [HIGH] CWE-770 CVE-2021-34741: A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security A A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation of incoming emails. An attacker could exploit this vulnerab
nvd
CVE-2021-34698HIGHCVSS 7.5≥ 12.0, < 12.0.3-005≥ 12.5, < 12.5.2-007+1 more2021-10-06
CVE-2021-34698 [HIGH] CWE-401 CVE-2021-34698: A vulnerability in the proxy service of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could a A vulnerability in the proxy service of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to exhaust system memory and cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management in the proxy service of an affected device. An attacker could
nvd
CVE-2021-1534MEDIUMCVSS 5.3fixed in 14.0.12021-10-06
CVE-2021-1534 [MEDIUM] CWE-20 CVE-2021-1534: A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Secu A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. This vulnerability is due to improper processing of URLs. An attacker could exploit this vulnerability by crafting a URL in a
nvd
CVE-2021-1359HIGHCVSS 8.8≥ 11.8.0, < 12.0.3-005≥ 12.5.0, < 12.5.22021-07-08
CVE-2021-1359 [HIGH] CWE-112 CVE-2021-1359: A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (W A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied XML input for the web interface. An attacker could exploit this vulnerabil
nvd
CVE-2021-1566HIGHCVSS 7.4fixed in 12.5.3-035≥ 13.0, < 13.0.0-030+4 more2021-06-16
CVE-2021-1566 [HIGH] CWE-296 CVE-2021-1566: A vulnerability in the Cisco Advanced Malware Protection (AMP) for Endpoints integration of Cisco As A vulnerability in the Cisco Advanced Malware Protection (AMP) for Endpoints integration of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to intercept traffic between an affected device and the AMP servers. This vulnerability is due to improper certificate va
nvd
CVE-2020-3367HIGHCVSS 7.8fixed in 11.7.2-011≥ 11.8.0, < 11.8.2-009+2 more2020-11-18
CVE-2020-3367 [HIGH] CWE-78 CVE-2020-3367: A vulnerability in the log subscription subsystem of Cisco AsyncOS for the Cisco Secure Web Applianc A vulnerability in the log subscription subsystem of Cisco AsyncOS for the Cisco Secure Web Appliance (formerly Web Security Appliance) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied input for the web interface and CLI. An atta
nvd
CVE-2020-3568MEDIUMCVSS 5.8≤ 13.5.22020-10-08
CVE-2020-3568 [MEDIUM] CWE-20 CVE-2020-3568: A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Secu A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. The vulnerability is due to insufficient input validation of URLs. An attacker could exploit this vulnerability by crafting a
nvd
CVE-2019-1947HIGHCVSS 8.6v12.1.0-0852020-09-23
CVE-2019-1947 [HIGH] CWE-20 CVE-2019-1947: A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Sec A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause the CPU utilization to increase to 100 percent, causing a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of email message
nvd
CVE-2019-1983MEDIUMCVSS 5.3fixed in 11.0.1-161≥ 12.0, ≤ 12.5.0-633+2 more2020-09-23
CVE-2019-1983 [MEDIUM] CWE-20 CVE-2019-1983: A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Sec A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause repeated crashes in some internal processes that are running on the affected devices, resulting in a denial of service (D
nvd
CVE-2020-3546MEDIUMCVSS 5.3≤ 13.5.12020-09-04
CVE-2020-3546 [MEDIUM] CWE-20 CVE-2020-3546: A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Secu A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to insufficient validation of requests that are sent to the web-based management interface. An attacker c
nvd
CVE-2020-3547MEDIUMCVSS 6.5≤ 13.5.1-277≤ 13.6.1-193+1 more2020-09-04
CVE-2020-3547 [MEDIUM] CWE-200 CVE-2020-3547: A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Secu A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability exists because an inse
nvd
CVE-2020-3368MEDIUMCVSS 5.8fixed in 13.5.02020-06-18
CVE-2020-3368 [MEDIUM] CWE-20 CVE-2020-3368: A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Secu A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. The vulnerability is due to insufficient input validation of URLs. An attacker could exploit this vulnerability by crafting t
nvd
CVE-2019-15956HIGHCVSS 8.8≥ 10.1, < 10.1.5-004≥ 10.5, < 11.5.3-016+1 more2019-11-26
CVE-2019-15956 [HIGH] CWE-284 CVE-2019-15956: A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security App A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform an unauthorized system reset on an affected device. The vulnerability is due to improper authorization controls for a specific URL in the web management interface. An attacker could e
nvd
CVE-2019-1886HIGHCVSS 8.6≥ 10.5, < 10.5.5-005≥ 11.5, < 11.5.2-0202019-07-04
CVE-2019-1886 [HIGH] CWE-20 CVE-2019-1886: A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Secure Sockets Layer (SSL) server certificates. An attacker could exploit this vulnerability by installing a malformed ce
nvd
CVE-2019-1884MEDIUMCVSS 6.5≥ 10.1, < 10.5.5-005≥ 11.5, < 11.5.2-020+1 more2019-07-04
CVE-2019-1884 [MEDIUM] CWE-20 CVE-2019-1884: A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appl A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation mechanisms for certain fields in HTTP/HTTPS requests sent through an a
nvd