Cisco Email Security Appliance vulnerabilities
46 known vulnerabilities affecting cisco/email_security_appliance.
Total CVEs
46
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH19MEDIUM26
Vulnerabilities
Page 3 of 3
CVE-2020-3137P4MEDIUMCVSS 6.1≤ 13.0.02020-09-23
CVE-2020-3137 [MEDIUM] CWE-79 CVE-2020-3137: A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) could
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability exists because the web-based management interface of the affected device
nvd
CVE-2017-6661P4MEDIUMCVSS 6.1v10.0.0-203v10.1.0-0492017-06-13
CVE-2017-6661 [MEDIUM] CWE-79 CVE-2017-6661: A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) and Ci
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device, aka Message Tracking XSS. More Info
nvd
CVE-2016-6465P4MEDIUMCVSS 4.3v8.5.7-042v9.7.2-047+2 more2016-12-14
CVE-2016-6465 [MEDIUM] CWE-20 CVE-2016-6465: A vulnerability in the content filtering functionality of Cisco AsyncOS Software for Cisco Email Sec
A vulnerability in the content filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances and Cisco Web Security Appliances could allow an unauthenticated, remote attacker to bypass user filters that are configured for an affected device. Affected Products: This vulnerability affects all releases prior to the first fixed rele
nvd
CVE-2017-6783P4MEDIUMCVSS 4.3v9.7.2-0652017-08-17
CVE-2017-6783 [MEDIUM] CWE-200 CVE-2017-6783: A vulnerability in SNMP polling for the Cisco Web Security Appliance (WSA), Email Security Appliance
A vulnerability in SNMP polling for the Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to discover confidential information about the appliances that should be available only to an administrative user. The vulnerability occurs because the
nvd
CVE-2015-4236P4MEDIUMCVSS 4.3v8.5.6-0742015-07-10
CVE-2015-4236 [MEDIUM] CWE-399 CVE-2015-4236: Cisco AsyncOS on Email Security Appliance (ESA) devices with software 8.5.6-073, 8.5.6-074, and 9.0.
Cisco AsyncOS on Email Security Appliance (ESA) devices with software 8.5.6-073, 8.5.6-074, and 9.0.0-461, when clustering is enabled, allows remote attackers to cause a denial of service (clustering and SSH outage) via a packet flood, aka Bug IDs CSCur13704 and CSCuq05636.
nvd
CVE-2015-4288P4MEDIUMCVSS 4.3v8.5.7-0422015-07-29
CVE-2015-4288 [MEDIUM] CWE-310 CVE-2015-4288: The LDAP implementation on the Cisco Web Security Appliance (WSA) 8.5.0-000, Email Security Applianc
The LDAP implementation on the Cisco Web Security Appliance (WSA) 8.5.0-000, Email Security Appliance (ESA) 8.5.7-042, and Content Security Management Appliance (SMA) 8.3.6-048 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate, aka B
nvd
← Previous3 / 3