cbcvebase.

Cisco Web Security Appliance vulnerabilities

24 known vulnerabilities affecting cisco/cisco_web_security_appliance.

Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH9MEDIUM15

Vulnerabilities

Page 2 of 2
CVE-2023-20120P4MEDIUMCVSS 6.1vn/a2023-06-28
CVE-2023-20120 [MEDIUM] CWE-79 CVE-2023-20120: Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco S Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to conduct a cross-site scripting (XSS) a
nvd
CVE-2020-3117P4MEDIUMCVSS 4.7vn/a2020-09-23
CVE-2020-3117 [MEDIUM] CWE-113 CVE-2020-3117: A vulnerability in the API Framework of Cisco AsyncOS for Cisco Web Security Appliance (WSA) and Cis A vulnerability in the API Framework of Cisco AsyncOS for Cisco Web Security Appliance (WSA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to inject crafted HTTP headers in the web server's response. The vulnerability is due to insufficient validation of user input. An attacker could exploit this
nvd
CVE-2023-20028P4MEDIUMCVSS 5.4vn/a2023-06-28
CVE-2023-20028 [MEDIUM] CWE-79 CVE-2023-20028: Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco S Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to conduct a cross-site scripting (XSS) a
nvd
CVE-2021-1271P4MEDIUMCVSS 4.8vn/a2021-01-20
CVE-2021-1271 [MEDIUM] CWE-79 CVE-2021-1271: A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Web Security Applia A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists because the web-based management interface does not properly val
nvd