Cisco Email Security Appliance vulnerabilities
46 known vulnerabilities affecting cisco/email_security_appliance.
Total CVEs
46
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH19MEDIUM26
Vulnerabilities
Page 1 of 3
CVE-2022-20798P2CRITICALCVSS 9.8≥ 14.0, < 14.0.1-033v7.1.52022-06-15
CVE-2022-20798 [CRITICAL] CWE-287 CVE-2022-20798: A vulnerability in the external authentication functionality of Cisco Secure Email and Web Manager,
A vulnerability in the external authentication functionality of Cisco Secure Email and Web Manager, formerly known as Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass authentication and log in to the web management interface of an affected device. This vuln
nvd
CVE-2019-1947P3HIGHCVSS 8.6v11.1.0-1312020-09-23
CVE-2019-1947 [HIGH] CWE-20 CVE-2019-1947: A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Sec
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause the CPU utilization to increase to 100 percent, causing a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of email message
nvd
CVE-2022-20664P3HIGHCVSS 7.7fixed in 14.0.2-0202022-06-15
CVE-2022-20664 [HIGH] CWE-497 CVE-2022-20664: A vulnerability in the web management interface of Cisco Secure Email and Web Manager, formerly Cisc
A vulnerability in the web management interface of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an authenticated, remote attacker to retrieve sensitive information from a Lightweight Directory Access Protocol (LDAP) external authentication server connected
nvd
CVE-2016-1480P3HIGHCVSS 7.5v8.0.1-023v8.0_base+29 more2016-10-28
CVE-2016-1480 [HIGH] CWE-388 CVE-2016-1480: A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Softwar
A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. Affected Products: all releases prior to the first fixed release of Cisco AsyncO
nvd
CVE-2019-1921P3HIGHCVSS 7.5v12.0.0-4192019-07-06
CVE-2019-1921 [HIGH] CWE-20 CVE-2019-1921: A vulnerability in the attachment scanning of Cisco AsyncOS Software for Cisco Email Security Applia
A vulnerability in the attachment scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper input validation of the email body. An attacker could exploit this vulnerability by naming a malicious attach
nvd
CVE-2023-20009P3HIGHCVSS 7.2fixed in 12.5.3-041≥ 13.0.0, < 13.0.5-007+3 more2023-03-01
CVE-2023-20009 [HIGH] CWE-20 CVE-2023-20009: A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cis
A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow an authenticated remote attacker and or authenticated local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user credential with at least a [[privilege of
nvd
CVE-2016-6357P3HIGHCVSS 7.5v9.7.1-066v9.9.6-0262016-10-28
CVE-2016-6357 [HIGH] CWE-388 CVE-2016-6357: A vulnerability in the configured security policies, including drop email filtering, in Cisco AsyncO
A vulnerability in the configured security policies, including drop email filtering, in Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass a configured drop filter by using an email with a corrupted attachment. More Information: CSCuz01651. Known Affected Releases: 10.0.9-015 9.7.1-066 9.9.6-
nvd
CVE-2020-3133P3HIGHCVSS 7.5fixed in 13.02020-09-23
CVE-2020-3133 [HIGH] CWE-20 CVE-2020-3133: A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security App
A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured filters on the device. The vulnerability is due to improper validation of incoming emails. An attacker could exploit this vulnerability by sending a crafted email message to
nvd
CVE-2016-6372P3HIGHCVSS 7.5v8.0.1-023v8.0_base+33 more2016-10-28
CVE-2016-6372 [HIGH] CWE-20 CVE-2016-6372: A vulnerability in the email message and content filtering for malformed Multipurpose Internet Mail
A vulnerability in the email message and content filtering for malformed Multipurpose Internet Mail Extensions (MIME) headers of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of the targeted device. Emails that should
nvd
CVE-2020-3548P3HIGHCVSS 7.5≤ 13.5.1-2772024-11-18
CVE-2020-3548 [HIGH] CWE-407 CVE-2020-3548: A vulnerability in the Transport Layer Security (TLS) protocol implementation of Cisco AsyncOS
A vulnerability in the Transport Layer Security (TLS) protocol implementation of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition.
The vulnerability is due to inefficient processing of incoming TLS
nvd
CVE-2016-1486P3HIGHCVSS 7.5v8.5.0-000v8.5.0-er1-198+28 more2016-10-28
CVE-2016-1486 [HIGH] CWE-19 CVE-2016-1486: A vulnerability in the email attachment scanning functionality of the Advanced Malware Protection (A
A vulnerability in the email attachment scanning functionality of the Advanced Malware Protection (AMP) feature of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, remote attacker to cause an affected device to stop scanning and forwarding email messages due to a denial of service (DoS) condition. Affected Produc
nvd
CVE-2019-1933P3HIGHCVSS 7.4v11.1.2-0232019-07-06
CVE-2019-1933 [HIGH] CWE-20 CVE-2019-1933: A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security App
A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured filters on the device. The vulnerability is due to improper input validation of certain email fields. An attacker could exploit this vulnerability by sending a crafted email
nvd
CVE-2016-6356P3HIGHCVSS 7.5v3.3.1-09v7.1.0+54 more2016-10-28
CVE-2016-6356 [HIGH] CWE-20 CVE-2016-6356: A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Sec
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, remote attacker to cause an affected device to stop scanning and forwarding email messages due to a denial of service (DoS) condition. Affected Products: This vulnerability affects all releases prior to the
nvd
CVE-2016-6360P3HIGHCVSS 7.5v9.5.0-000v9.5.0-201+4 more2016-10-28
CVE-2016-6360 [HIGH] CWE-20 CVE-2016-6360: A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and W
A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition due to the AMP process unexpectedly restarting. Affected Products: Cisco AsyncOS Software for Email Security Appliances (ESA)
nvd
CVE-2016-1481P3HIGHCVSS 7.5v8.5.0-000v8.5.0-er1-198+28 more2016-10-28
CVE-2016-1481 [HIGH] CWE-20 CVE-2016-1481: A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Sec
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.Affected Products: This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for Ci
nvd
CVE-2016-1405P3HIGHCVSS 7.5v9.6.0-0422016-06-08
CVE-2016-1405 [HIGH] CWE-119 CVE-2016-1405: libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection (AMP) on Cisco Emai
libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection (AMP) on Cisco Email Security Appliance (ESA) devices before 9.7.0-125 and Web Security Appliance (WSA) devices before 9.0.1-135 and 9.1.x before 9.1.1-041, allows remote attackers to cause a denial of service (AMP process restart) via a crafted document, aka Bug IDs CSCuv7
nvd
CVE-2022-20960P3HIGHCVSS 7.5fixed in 14.2.1-015≥ 14.3.0, < 14.3.0-0202022-11-04
CVE-2022-20960 [HIGH] CWE-400 CVE-2022-20960: A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an un
A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper handling of certain TLS connections that are processed by an affected device. An attacker could exploit this vulnerab
nvd
CVE-2015-6321P3HIGHCVSS 7.8v7.6.1-000v7.6.3-000+12 more2015-11-06
CVE-2015-6321 [HIGH] CWE-399 CVE-2015-6321: Cisco AsyncOS before 8.5.7-042, 9.x before 9.1.0-032, 9.1.x before 9.1.1-023, and 9.5.x and 9.6.x be
Cisco AsyncOS before 8.5.7-042, 9.x before 9.1.0-032, 9.1.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-042 on Email Security Appliance (ESA) devices; before 9.1.0-032, 9.1.1 before 9.1.1-005, and 9.5.x before 9.5.0-025 on Content Security Management Appliance (SMA) devices; and before 7.7.0-725 and 8.x before 8.0.8-113 on Web Security Appliance
nvd
CVE-2016-6358P3HIGHCVSS 7.5v9.7.1-066v9.7.2-046+4 more2016-10-28
CVE-2016-6358 [HIGH] CWE-20 CVE-2016-6358: A vulnerability in local FTP to the Cisco Email Security Appliance (ESA) could allow an unauthentica
A vulnerability in local FTP to the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition when the FTP application unexpectedly quits. More Information: CSCux68539. Known Affected Releases: 9.1.0-032 9.7.1-000. Known Fixed Releases: 9.1.1-038.
nvd
CVE-2020-3181P3MEDIUMCVSS 6.5fixed in 13.0.02020-03-04
CVE-2020-3181 [MEDIUM] CWE-400 CVE-2020-3181: A vulnerability in the malware detection functionality in Cisco Advanced Malware Protection (AMP) in
A vulnerability in the malware detection functionality in Cisco Advanced Malware Protection (AMP) in Cisco AsyncOS Software for Cisco Email Security Appliances (ESAs) could allow an unauthenticated remote attacker to exhaust resources on an affected device. The vulnerability is due to insufficient control over system memory allocation. An attacker cou
nvd
1 / 3Next →