cbcvebase.

Cisco Email Security Appliance vulnerabilities

29 known vulnerabilities affecting cisco/cisco_email_security_appliance.

Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH11MEDIUM17

Vulnerabilities

Page 2 of 2
CVE-2019-1844P4MEDIUMCVSS 5.3≥ unspecified, < 11.1.1-0302019-05-03
CVE-2019-1844 [MEDIUM] CWE-20 CVE-2019-1844: A vulnerability in certain attachment detection mechanisms of the Cisco Email Security Appliance (ES A vulnerability in certain attachment detection mechanisms of the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of an affected device. The vulnerability is due to improper detection of certain content sent to an affected device. An attacker could exploit this vulnerability by
nvd
CVE-2019-1831P4MEDIUMCVSS 5.3v11.1.2-0232019-04-18
CVE-2019-1831 [MEDIUM] CWE-20 CVE-2019-1831: A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security App A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper input validation of the email body. An attacker could exploit this vulnerability by inserting specific c
nvd
CVE-2021-1534P4MEDIUMCVSS 5.3vn/a2021-10-06
CVE-2021-1534 [MEDIUM] CWE-20 CVE-2021-1534: A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Secu A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. This vulnerability is due to improper processing of URLs. An attacker could exploit this vulnerability by crafting a URL in a
nvd
CVE-2019-15988P4MEDIUMCVSS 5.3≥ unspecified, < n/a2019-11-26
CVE-2019-15988 [MEDIUM] CWE-20 CVE-2019-15988: A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Secu A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. The vulnerability is due to insufficient input validation of URLs. An attacker could exploit this vulnerability by crafting
nvd
CVE-2020-3546P4MEDIUMCVSS 5.3vn/a2020-09-04
CVE-2020-3546 [MEDIUM] CWE-20 CVE-2020-3546: A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Secu A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to insufficient validation of requests that are sent to the web-based management interface. An attacker c
nvd
CVE-2020-3132P4MEDIUMCVSS 5.9≥ unspecified, < n/a2020-02-19
CVE-2020-3132 [MEDIUM] CWE-400 CVE-2020-3132: A vulnerability in the email message scanning feature of Cisco AsyncOS Software for Cisco Email Secu A vulnerability in the email message scanning feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a temporary denial of service (DoS) condition on an affected device. The vulnerability is due to inadequate parsing mechanisms for specific email body components. An attacker
nvd
CVE-2019-1983P4MEDIUMCVSS 5.3vn/a2020-09-23
CVE-2019-1983 [MEDIUM] CWE-20 CVE-2019-1983: A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Sec A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause repeated crashes in some internal processes that are running on the affected devices, resulting in a denial of service (D
nvd
CVE-2020-3137P4MEDIUMCVSS 6.1vn/a2020-09-23
CVE-2020-3137 [MEDIUM] CWE-79 CVE-2020-3137: A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) could A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability exists because the web-based management interface of the affected device
nvd
CVE-2019-15971P4MEDIUMCVSS 4.3≥ unspecified, < n/a2019-11-26
CVE-2019-15971 [MEDIUM] CWE-20 CVE-2019-15971: A vulnerability in the MP3 detection engine of Cisco AsyncOS Software for Cisco Email Security Appli A vulnerability in the MP3 detection engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper validation of certain MP3 file types. An attacker could exploit this vulnerability by sending a crafted
nvd
Cisco Email Security Appliance vulnerabilities | cvebase