cbcvebase.

Cisco Secure Email vulnerabilities

28 known vulnerabilities affecting cisco/cisco_secure_email.

Total CVEs
28
CISA KEV
2
actively exploited
Public exploits
0
Exploited in wild
2
Severity breakdown
CRITICAL6HIGH7MEDIUM15

Vulnerabilities

Page 2 of 2
CVE-2024-20392P4MEDIUMCVSS 6.1v11.0.3-238v11.1.0-069+19 more2024-05-15
CVE-2024-20392 [MEDIUM] CWE-113 CVE-2024-20392: A vulnerability in the web-based management API of Cisco AsyncOS Software for Cisco Secure Email Gat A vulnerability in the web-based management API of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to insufficient input validation of some parameters that are passed to the web-based management API of the affected system. An
nvd
CVE-2020-26082P4MEDIUMCVSS 5.3vN/A2023-08-04
CVE-2020-26082 [MEDIUM] CWE-20 CVE-2020-26082: A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security A A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass content filters that are configured on an affected device. The vulnerability is due to improper handling of password-protected zip files. An attacker could exploit this vulnerabil
nvd
CVE-2024-20258P4MEDIUMCVSS 6.1v11.0.3-238v11.1.0-069+20 more2024-05-15
CVE-2024-20258 [MEDIUM] CWE-79 CVE-2024-20258: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vul
nvd
CVE-2022-20772P4MEDIUMCVSS 5.3v13.5.1-277v14.0.0-698+1 more2022-11-04
CVE-2022-20772 [MEDIUM] CWE-113 CVE-2022-20772: A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to the failure of the application or its environment to properly sanitize input values. An attacker could exploit this vulnerability by
nvd
CVE-2024-20504P4MEDIUMCVSS 5.4v14.0.0-698v14.2.0-620+6 more2024-11-06
CVE-2024-20504 [MEDIUM] CWE-80 CVE-2024-20504: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validatio
nvd
CVE-2025-20207P4MEDIUMCVSS 4.3v14.0.0-698v13.5.1-277+10 more2025-02-05
CVE-2025-20207 [MEDIUM] CWE-200 CVE-2025-20207: A vulnerability in Simple Network Management Protocol (SNMP) polling for Cisco Secure Email and Web A vulnerability in Simple Network Management Protocol (SNMP) polling for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, remote attacker to obtain confidential information about the underlying operating system. This vulnerability exists because the appliances do not protect
nvd
CVE-2024-20257P4MEDIUMCVSS 4.8v11.0.3-238v11.1.0-069+20 more2024-05-15
CVE-2024-20257 [MEDIUM] CWE-79 CVE-2024-20257: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.r This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of
nvd
CVE-2025-20180P4MEDIUMCVSS 4.8v14.0.0-698v13.5.1-277+14 more2025-02-05
CVE-2025-20180 [MEDIUM] CWE-79 CVE-2025-20180: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An att
nvd
Cisco Secure Email vulnerabilities | cvebase