cbcvebase.

Cisco Asyncos vulnerabilities

49 known vulnerabilities affecting cisco/asyncos.

Total CVEs
49
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH20MEDIUM28

Vulnerabilities

Page 3 of 3
CVE-2014-3381P4MEDIUMCVSS 5.0≤ 8.52014-10-19
CVE-2014-3381 [MEDIUM] CWE-264 CVE-2014-3381: The ZIP inspection engine in Cisco AsyncOS 8.5 and earlier on the Cisco Email Security Appliance (ES The ZIP inspection engine in Cisco AsyncOS 8.5 and earlier on the Cisco Email Security Appliance (ESA) does not properly analyze ZIP archives, which allows remote attackers to bypass malware filtering via a crafted archive, aka Bug ID CSCup07934.
nvd
CVE-2022-20781P4MEDIUMCVSS 5.4fixed in 14.52022-04-06
CVE-2022-20781 [MEDIUM] CWE-79 CVE-2022-20781: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Web Securi A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists because the web-based management interface does not p
nvd
CVE-2020-3122P4MEDIUMCVSS 5.3v11.0.0-1282025-03-04
CVE-2020-3122 [MEDIUM] CWE-284 CVE-2020-3122: A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Content Security Ma A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to obtain sensitive network information.
nvd
CVE-2017-12215P4HIGHCVSS 7.1v9.0v9.1+5 more2017-09-21
CVE-2017-12215 [HIGH] CWE-20 CVE-2017-12215: A vulnerability in the email message filtering feature of Cisco AsyncOS Software for the Cisco Email A vulnerability in the email message filtering feature of Cisco AsyncOS Software for the Cisco Email Security Appliance could allow an unauthenticated, remote attacker to cause an affected device to run out of memory and stop scanning and forwarding email messages. When system memory is depleted, it can cause the filtering process to crash, resulting i
nvd
CVE-2024-20504P4MEDIUMCVSS 5.4v14.0.0-698v14.2.0-620+34 more2024-11-06
CVE-2024-20504 [MEDIUM] CWE-80 CVE-2024-20504: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validatio
nvd
CVE-2015-0605P4MEDIUMCVSS 4.3≤ 8.52015-02-07
CVE-2015-0605 [MEDIUM] CWE-264 CVE-2015-0605: The uuencode inspection engine in Cisco AsyncOS on Cisco Email Security Appliance (ESA) devices 8.5 The uuencode inspection engine in Cisco AsyncOS on Cisco Email Security Appliance (ESA) devices 8.5 and earlier allows remote attackers to bypass intended content restrictions via a crafted e-mail attachment with uuencode encoding, aka Bug ID CSCzv54343.
nvd
CVE-2024-20257P4MEDIUMCVSS 4.8v11.0.3-238v11.1.0-069+20 more2024-05-15
CVE-2024-20257 [MEDIUM] CWE-79 CVE-2024-20257: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.r This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of
nvd
CVE-2025-20180P4MEDIUMCVSS 4.8v12.8.1-002v12.8.1-021+36 more2025-02-05
CVE-2025-20180 [MEDIUM] CWE-79 CVE-2025-20180: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An att
nvd
CVE-2024-20256P4MEDIUMCVSS 4.8v11.7.0-406v11.7.0-418+46 more2024-05-15
CVE-2024-20256 [MEDIUM] CWE-79 CVE-2024-20256: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Web Appliance could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulne
nvd