Cisco Web Security Appliance vulnerabilities

34 known vulnerabilities affecting cisco/cisco_web_security_appliance.

Total CVEs
34
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH13MEDIUM21

Vulnerabilities

Page 1 of 2
CVE-2023-20120MEDIUMCVSS 6.1vn/a2023-06-28
CVE-2023-20120 [MEDIUM] CWE-79 CVE-2023-20120: Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco S Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to conduct a cross-site scripting (XSS) a
cvelistv5nvd
CVE-2023-20028MEDIUMCVSS 5.4vn/a2023-06-28
CVE-2023-20028 [MEDIUM] CWE-79 CVE-2023-20028: Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco S Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to conduct a cross-site scripting (XSS) a
cvelistv5nvd
CVE-2022-20784MEDIUMCVSS 5.3vn/a2022-04-06
CVE-2022-20784 [MEDIUM] CWE-20 CVE-2022-20784: A vulnerability in the Web-Based Reputation Score (WBRS) engine of Cisco AsyncOS Software for Cisco A vulnerability in the Web-Based Reputation Score (WBRS) engine of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass established web request policies and access blocked content on an affected device. This vulnerability is due to incorrect handling of certain character combinations i
cvelistv5nvd
CVE-2022-20781MEDIUMCVSS 5.4vn/a2022-04-06
CVE-2022-20781 [MEDIUM] CWE-79 CVE-2022-20781: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Web Securi A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists because the web-based management interface does not p
cvelistv5nvd
CVE-2022-20675MEDIUMCVSS 5.3vn/a2022-04-06
CVE-2022-20675 [MEDIUM] CWE-248 CVE-2022-20675: A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appl A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Secure Email and Web Manager, formerly Security Management Appliance, could allow an unauthenticated, remote attacker to crash the Simple Network Management Protocol (SNMP) service, resulting in a denial of service (DoS) conditi
cvelistv5nvd
CVE-2021-34698HIGHCVSS 7.5vn/a2021-10-06
CVE-2021-34698 [HIGH] CWE-401 CVE-2021-34698: A vulnerability in the proxy service of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could a A vulnerability in the proxy service of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to exhaust system memory and cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management in the proxy service of an affected device. An attacker could
cvelistv5nvd
CVE-2021-34749HIGHCVSS 8.6vn/a2021-08-18
CVE-2021-34749 [HIGH] CWE-200 CVE-2021-34749: A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Applianc A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), and the Snort detection engine could allow an unauthenticated, remote attacker to bypass filtering technology on an affected device and exfiltrate data from a compromised host. This vulnerability is due to
cvelistv5nvd
CVE-2021-1359HIGHCVSS 8.8vn/a2021-07-08
CVE-2021-1359 [HIGH] CWE-112 CVE-2021-1359: A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (W A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied XML input for the web interface. An attacker could exploit this vulnerabil
cvelistv5nvd
CVE-2021-1566HIGHCVSS 7.4vn/a2021-06-16
CVE-2021-1566 [HIGH] CWE-296 CVE-2021-1566: A vulnerability in the Cisco Advanced Malware Protection (AMP) for Endpoints integration of Cisco As A vulnerability in the Cisco Advanced Malware Protection (AMP) for Endpoints integration of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to intercept traffic between an affected device and the AMP servers. This vulnerability is due to improper certificate va
cvelistv5nvd
CVE-2021-1490MEDIUMCVSS 6.1vn/a2021-05-06
CVE-2021-1490 [MEDIUM] CWE-79 CVE-2021-1490: A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Web Security Applia A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to improper validation of user-supplied input in the web-based manag
cvelistv5nvd
CVE-2021-1516MEDIUMCVSS 6.5vn/a2021-05-06
CVE-2021-1516 [MEDIUM] CWE-540 CVE-2021-1516: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Content Se A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA), Cisco Email Security Appliance (ESA), and Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability exists because confide
cvelistv5nvd
CVE-2021-1129MEDIUMCVSS 5.3vn/a2021-01-20
CVE-2021-1129 [MEDIUM] CWE-201 CVE-2021-1129: A vulnerability in the authentication for the general purpose APIs implementation of Cisco Email Sec A vulnerability in the authentication for the general purpose APIs implementation of Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to access general system information and certain configuration information from an affected
cvelistv5nvd
CVE-2021-1271MEDIUMCVSS 4.8vn/a2021-01-20
CVE-2021-1271 [MEDIUM] CWE-79 CVE-2021-1271: A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Web Security Applia A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists because the web-based management interface does not properly val
cvelistv5nvd
CVE-2020-3367HIGHCVSS 7.8vn/a2020-11-18
CVE-2020-3367 [HIGH] CWE-78 CVE-2020-3367: A vulnerability in the log subscription subsystem of Cisco AsyncOS for the Cisco Secure Web Applianc A vulnerability in the log subscription subsystem of Cisco AsyncOS for the Cisco Secure Web Appliance (formerly Web Security Appliance) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied input for the web interface and CLI. An atta
cvelistv5nvd
CVE-2019-15969MEDIUMCVSS 6.1vn/a2020-09-23
CVE-2019-15969 [MEDIUM] CWE-79 CVE-2019-15969: A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could al A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interfac
cvelistv5nvd
CVE-2020-3117MEDIUMCVSS 4.7vn/a2020-09-23
CVE-2020-3117 [MEDIUM] CWE-113 CVE-2020-3117: A vulnerability in the API Framework of Cisco AsyncOS for Cisco Web Security Appliance (WSA) and Cis A vulnerability in the API Framework of Cisco AsyncOS for Cisco Web Security Appliance (WSA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to inject crafted HTTP headers in the web server's response. The vulnerability is due to insufficient validation of user input. An attacker could exploit this
cvelistv5nvd
CVE-2020-3547MEDIUMCVSS 6.5vn/a2020-09-04
CVE-2020-3547 [MEDIUM] CWE-200 CVE-2020-3547: A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Secu A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability exists because an inse
cvelistv5nvd
CVE-2020-3164MEDIUMCVSS 5.3≥ unspecified, < n/a2020-03-04
CVE-2020-3164 [MEDIUM] CWE-20 CVE-2020-3164: A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appl A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated remote attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition. The vul
cvelistv5nvd
CVE-2019-15956HIGHCVSS 8.8≥ unspecified, < n/a2019-11-26
CVE-2019-15956 [HIGH] CWE-284 CVE-2019-15956: A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security App A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform an unauthorized system reset on an affected device. The vulnerability is due to improper authorization controls for a specific URL in the web management interface. An attacker could e
cvelistv5nvd
CVE-2019-1886HIGHCVSS 8.6≥ unspecified, < 10.5.5-0052019-07-04
CVE-2019-1886 [HIGH] CWE-20 CVE-2019-1886: A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Secure Sockets Layer (SSL) server certificates. An attacker could exploit this vulnerability by installing a malformed ce
cvelistv5nvd