Cisco Secure Email And Web Manager vulnerabilities

7 known vulnerabilities affecting cisco/secure_email_and_web_manager.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2023-20120MEDIUMCVSS 6.1v14.0.0-418v14.0.1-033+3 more2023-06-28
CVE-2023-20120 [MEDIUM] CWE-79 CVE-2023-20120: Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco S Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to conduct a cross-site scripting (XSS) a
nvd
CVE-2023-20119MEDIUMCVSS 6.1v14.0.0-418v14.0.1-033+3 more2023-06-28
CVE-2023-20119 [MEDIUM] CWE-79 CVE-2023-20119: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, formerly known as Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient
nvd
CVE-2023-20028MEDIUMCVSS 5.4v14.0.0-418v14.0.1-033+3 more2023-06-28
CVE-2023-20028 [MEDIUM] CWE-79 CVE-2023-20028: Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco S Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to conduct a cross-site scripting (XSS) a
nvd
CVE-2023-20009HIGHCVSS 7.2fixed in 12.8.1-021≥ 13.8.0, < 13.8.1-108+2 more2023-03-01
CVE-2023-20009 [MEDIUM] CWE-20 CVE-2023-20009: A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cis A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow an authenticated remote attacker and or authenticated local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user credential with at least a [[privilege
nvd
CVE-2022-20798CRITICALCVSS 9.8≥ 13.0, < 13.0.0-277≥ 13.6, < 13.6.2-090+3 more2022-06-15
CVE-2022-20798 [CRITICAL] CWE-287 CVE-2022-20798: A vulnerability in the external authentication functionality of Cisco Secure Email and Web Manager, A vulnerability in the external authentication functionality of Cisco Secure Email and Web Manager, formerly known as Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass authentication and log in to the web management interface of an affected device. This vuln
nvd
CVE-2022-20664HIGHCVSS 7.7fixed in 13.6.2-090≥ 14.1, < 14.1.0-2272022-06-15
CVE-2022-20664 [HIGH] CWE-497 CVE-2022-20664: A vulnerability in the web management interface of Cisco Secure Email and Web Manager, formerly Cisc A vulnerability in the web management interface of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an authenticated, remote attacker to retrieve sensitive information from a Lightweight Directory Access Protocol (LDAP) external authentication server connected
nvd
CVE-2021-1561MEDIUMCVSS 5.4≤ 14.12021-08-18
CVE-2021-1561 [MEDIUM] CWE-302 CVE-2021-1561: A vulnerability in the spam quarantine feature of Cisco Secure Email and Web Manager, formerly Cisco A vulnerability in the spam quarantine feature of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), could allow an authenticated, remote attacker to gain unauthorized access and modify the spam quarantine settings of another user. This vulnerability exists because access to the spam quarantine feature is not prope
nvd