Cisco Email Security Appliance vulnerabilities
46 known vulnerabilities affecting cisco/email_security_appliance.
Total CVEs
46
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH19MEDIUM26
Vulnerabilities
Page 2 of 3
CVE-2020-3447P3MEDIUMCVSS 6.5fixed in 13.5.12020-08-17
CVE-2020-3447 [MEDIUM] CWE-532 CVE-2020-3447: A vulnerability in the CLI of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco Async
A vulnerability in the CLI of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to excessive verbosity in certain log subscriptions. An attacker could
nvd
CVE-2023-20075P3MEDIUMCVSS 6.7≥ 12.5.0, < 12.5.3-041≥ 13.0.0, < 13.0.5-007+3 more2023-03-01
CVE-2023-20075 [MEDIUM] CWE-77 CVE-2023-20075: Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker
Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary commands.
These vulnerability is due to improper input validation in the CLI. An attacker could exploit this vulnerability by injecting operating system commands into a legitimate command. A successful exploit could allow the atta
nvd
CVE-2015-6291P4HIGHCVSS 7.8v7.7.0-000v7.7.1-000+14 more2015-11-06
CVE-2015-6291 [HIGH] CWE-20 CVE-2015-6291: Cisco AsyncOS before 8.5.7-043, 9.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-046 on Email
Cisco AsyncOS before 8.5.7-043, 9.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-046 on Email Security Appliance (ESA) devices mishandles malformed fields during body-contains, attachment-contains, every-attachment-contains, attachment-binary-contains, dictionary-match, and attachment-dictionary-match filtering, which allows remote attackers to caus
nvd
CVE-2020-3134P4MEDIUMCVSS 6.5fixed in 13.02020-01-26
CVE-2020-3134 [MEDIUM] CWE-20 CVE-2020-3134: A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security A
A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper validation of zip files. An attacker could exploit this vulnerability by sending an em
nvd
CVE-2017-3800P4MEDIUMCVSS 5.8v9.7.1-066v9.7.1-hp2-207+1 more2017-01-26
CVE-2017-3800 [MEDIUM] CWE-20 CVE-2017-3800: A vulnerability in the content scanning engine of Cisco AsyncOS Software for Cisco Email Security Ap
A vulnerability in the content scanning engine of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured message or content filters on the device. Affected Products: This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for Cisco
nvd
CVE-2019-1905P4MEDIUMCVSS 5.8v11.1.2v12.0.02019-06-20
CVE-2019-1905 [MEDIUM] CWE-20 CVE-2019-1905: A vulnerability in the GZIP decompression engine of Cisco AsyncOS Software for Cisco Email Security
A vulnerability in the GZIP decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper validation of GZIP-formatted files. An attacker could exploit this vulnerability by sending a maliciou
nvd
CVE-2020-3370P4MEDIUMCVSS 5.8fixed in 13.0.1≥ 13.5.0, < 13.5.12020-07-16
CVE-2020-3370 [MEDIUM] CWE-20 CVE-2020-3370: A vulnerability in URL filtering of Cisco Content Security Management Appliance (SMA) could allow an
A vulnerability in URL filtering of Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to bypass URL filtering on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted, malicious HTTP request to an affected device. A
nvd
CVE-2016-1411P4MEDIUMCVSS 5.9v7.5.2-201v7.5.2-hp2-303+5 more2016-12-14
CVE-2016-1411 [MEDIUM] CWE-310 CVE-2016-1411: A vulnerability in the update functionality of Cisco AsyncOS Software for Cisco Email Security Appli
A vulnerability in the update functionality of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Management Security Appliance (SMA) could allow an unauthenticated, remote attacker to impersonate the update server. More Information: CSCul88715, CSCul94617, CSCul94627. Known Affected
nvd
CVE-2019-1844P4MEDIUMCVSS 5.3v11.1.0-1312019-05-03
CVE-2019-1844 [MEDIUM] CWE-20 CVE-2019-1844: A vulnerability in certain attachment detection mechanisms of the Cisco Email Security Appliance (ES
A vulnerability in certain attachment detection mechanisms of the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of an affected device. The vulnerability is due to improper detection of certain content sent to an affected device. An attacker could exploit this vulnerability by
nvd
CVE-2019-1831P4MEDIUMCVSS 5.3v11.1.2-023v12.0.0-2082019-04-18
CVE-2019-1831 [MEDIUM] CWE-20 CVE-2019-1831: A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security App
A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper input validation of the email body. An attacker could exploit this vulnerability by inserting specific c
nvd
CVE-2021-1129P4MEDIUMCVSS 5.3v13.0.02021-01-20
CVE-2021-1129 [MEDIUM] CWE-201 CVE-2021-1129: A vulnerability in the authentication for the general purpose APIs implementation of Cisco Email Sec
A vulnerability in the authentication for the general purpose APIs implementation of Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to access general system information and certain configuration information from an affected
nvd
CVE-2015-4184P4MEDIUMCVSS 5.0v3.331-09v7.5.1-gpl-022+1 more2015-06-13
CVE-2015-4184 [MEDIUM] CWE-20 CVE-2015-4184: The anti-spam scanner on Cisco Email Security Appliance (ESA) devices 3.3.1-09, 7.5.1-gpl-022, and 8
The anti-spam scanner on Cisco Email Security Appliance (ESA) devices 3.3.1-09, 7.5.1-gpl-022, and 8.5.6-074 allows remote attackers to bypass intended e-mail restrictions via a malformed DNS SPF record, aka Bug IDs CSCuu35853 and CSCuu37733.
nvd
CVE-2016-6416P4MEDIUMCVSS 5.9v9.6.0-000v9.6.0-042+4 more2016-10-05
CVE-2016-6416 [MEDIUM] CWE-119 CVE-2016-6416: The FTP service in Cisco AsyncOS on Email Security Appliance (ESA) devices 9.6.0-000 through 9.9.6-0
The FTP service in Cisco AsyncOS on Email Security Appliance (ESA) devices 9.6.0-000 through 9.9.6-026, Web Security Appliance (WSA) devices 9.0.0-162 through 9.5.0-444, and Content Security Management Appliance (SMA) devices allows remote attackers to cause a denial of service via a flood of FTP traffic, aka Bug IDs CSCuz82907, CSCuz84330, and CSCuz8
nvd
CVE-2015-6309P4MEDIUMCVSS 6.8v9.6.0-0422015-10-02
CVE-2015-6309 [MEDIUM] CWE-399 CVE-2015-6309: Cisco Email Security Appliance (ESA) 8.5.6-106 and 9.6.0-042 allows remote authenticated users to ca
Cisco Email Security Appliance (ESA) 8.5.6-106 and 9.6.0-042 allows remote authenticated users to cause a denial of service (file-descriptor consumption and device reload) via crafted HTTP requests, aka Bug ID CSCuw32211.
nvd
CVE-2020-3132P4MEDIUMCVSS 5.9fixed in 12.5.1-037fixed in 13.0.0-3752020-02-19
CVE-2020-3132 [MEDIUM] CWE-400 CVE-2020-3132: A vulnerability in the email message scanning feature of Cisco AsyncOS Software for Cisco Email Secu
A vulnerability in the email message scanning feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a temporary denial of service (DoS) condition on an affected device. The vulnerability is due to inadequate parsing mechanisms for specific email body components. An attacker
nvd
CVE-2019-1983P4MEDIUMCVSS 5.3v11.0.1-hp5-602v11.1.0-4042020-09-23
CVE-2019-1983 [MEDIUM] CWE-20 CVE-2019-1983: A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Sec
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause repeated crashes in some internal processes that are running on the affected devices, resulting in a denial of service (D
nvd
CVE-2016-1423P4MEDIUMCVSS 6.1v8.9.0v8.9.1-000+9 more2016-10-28
CVE-2016-1423 [MEDIUM] CWE-79 CVE-2016-1423: A vulnerability in the display of email messages in the Messages in Quarantine (MIQ) view in Cisco A
A vulnerability in the display of email messages in the Messages in Quarantine (MIQ) view in Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a user to click a malicious link in the MIQ view. The malicious link could be used to facilitate a cross-site scripting (XSS) or HTML injection attac
nvd
CVE-2020-3164P4MEDIUMCVSS 5.3≤ 13.0.0-3922020-03-04
CVE-2020-3164 [MEDIUM] CWE-20 CVE-2020-3164: A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appl
A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated remote attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition. The vul
nvd
CVE-2015-6285P4MEDIUMCVSS 6.4v7.6.0v8.0.02015-09-14
CVE-2015-6285 [MEDIUM] CWE-134 CVE-2015-6285: Format string vulnerability in Cisco Email Security Appliance (ESA) 7.6.0 and 8.0.0 allows remote at
Format string vulnerability in Cisco Email Security Appliance (ESA) 7.6.0 and 8.0.0 allows remote attackers to cause a denial of service (memory overwrite or service outage) via format string specifiers in an HTTP request, aka Bug ID CSCug21497.
nvd
CVE-2016-9202P4MEDIUMCVSS 6.1v9.1.1-036v9.1.2-023+14 more2016-12-14
CVE-2016-9202 [MEDIUM] CWE-79 CVE-2016-9202: A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) Switch
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) Switches could allow an unauthenticated, remote attacker to conduct a persistent cross-site scripting (XSS) attack against a user of the affected interface on an affected device. More Information: CSCvb37346. Known Affected Releases: 9.1.1-036 9.7.1-066.
nvd