Cisco Web Security Appliance vulnerabilities
55 known vulnerabilities affecting cisco/web_security_appliance.
Total CVEs
55
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH24MEDIUM29
Vulnerabilities
Page 1 of 3
CVE-2023-20120MEDIUMCVSS 6.1v14.0.0-418v14.0.1-033+3 more2023-06-28
CVE-2023-20120 [MEDIUM] CWE-79 CVE-2023-20120: Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco S
Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to conduct a cross-site scripting (XSS) a
nvd
CVE-2023-20119MEDIUMCVSS 6.1v14.0.0-418v14.0.1-033+3 more2023-06-28
CVE-2023-20119 [MEDIUM] CWE-79 CVE-2023-20119: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, formerly known as Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
This vulnerability is due to insufficient
nvd
CVE-2023-20028MEDIUMCVSS 5.4v14.0.0-418v14.0.1-033+3 more2023-06-28
CVE-2023-20028 [MEDIUM] CWE-79 CVE-2023-20028: Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco S
Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to conduct a cross-site scripting (XSS) a
nvd
CVE-2023-20032CRITICALCVSS 9.8fixed in 12.5.6≥ 14.0.0, < 14.0.4-005+2 more2023-03-01
CVE-2023-20032 [CRITICAL] CWE-120 CVE-2023-20032: On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed:
A vu
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed:
A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code.
This vulnerability is due to a missing buffer size
nvd
CVE-2022-20784MEDIUMCVSS 5.3≥ 11.7.0, < 14.0.22022-04-06
CVE-2022-20784 [MEDIUM] CWE-20 CVE-2022-20784: A vulnerability in the Web-Based Reputation Score (WBRS) engine of Cisco AsyncOS Software for Cisco
A vulnerability in the Web-Based Reputation Score (WBRS) engine of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass established web request policies and access blocked content on an affected device. This vulnerability is due to incorrect handling of certain character combinations i
nvd
CVE-2021-1359HIGHCVSS 8.8v11.8.0-429v11.8.0-4532021-07-08
CVE-2021-1359 [MEDIUM] CWE-112 CVE-2021-1359: A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (W
A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied XML input for the web interface. An attacker could exploit this vulnerab
nvd
CVE-2021-1490MEDIUMCVSS 6.1fixed in 14.02021-05-06
CVE-2021-1490 [MEDIUM] CWE-79 CVE-2021-1490: A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Web Security Applia
A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to improper validation of user-supplied input in the web-based manag
nvd
CVE-2021-1129MEDIUMCVSS 5.3v11.8.02021-01-20
CVE-2021-1129 [MEDIUM] CWE-201 CVE-2021-1129: A vulnerability in the authentication for the general purpose APIs implementation of Cisco Email Sec
A vulnerability in the authentication for the general purpose APIs implementation of Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to access general system information and certain configuration information from an affected
nvd
CVE-2019-15969MEDIUMCVSS 6.1fixed in 11.8.02020-09-23
CVE-2019-15969 [MEDIUM] CWE-79 CVE-2019-15969: A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could al
A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interfac
nvd
CVE-2020-3117MEDIUMCVSS 4.7v11.8.0-382v12.0.1-2682020-09-23
CVE-2020-3117 [MEDIUM] CWE-113 CVE-2020-3117: A vulnerability in the API Framework of Cisco AsyncOS for Cisco Web Security Appliance (WSA) and Cis
A vulnerability in the API Framework of Cisco AsyncOS for Cisco Web Security Appliance (WSA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to inject crafted HTTP headers in the web server's response. The vulnerability is due to insufficient validation of user input. An attacker could exploit this
nvd
CVE-2020-3164MEDIUMCVSS 5.3≤ 12.0.1-2682020-03-04
CVE-2020-3164 [MEDIUM] CWE-20 CVE-2020-3164: A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appl
A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated remote attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition. The vul
nvd
CVE-2019-15956HIGHCVSS 8.8v10.5.2-072v11.5.1-fcs-125+1 more2019-11-26
CVE-2019-15956 [HIGH] CWE-284 CVE-2019-15956: A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security App
A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform an unauthorized system reset on an affected device. The vulnerability is due to improper authorization controls for a specific URL in the web management interface. An attacker could e
nvd
CVE-2019-1886HIGHCVSS 8.6v10.5.2-072v10.5.3-025+1 more2019-07-04
CVE-2019-1886 [HIGH] CWE-20 CVE-2019-1886: A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an
A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Secure Sockets Layer (SSL) server certificates. An attacker could exploit this vulnerability by installing a malformed ce
nvd
CVE-2019-1884MEDIUMCVSS 6.5v10.1.4-017v10.5.2-072+2 more2019-07-04
CVE-2019-1884 [HIGH] CWE-20 CVE-2019-1884: A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appl
A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation mechanisms for certain fields in HTTP/HTTPS requests sent through an aff
nvd
CVE-2019-1816HIGHCVSS 7.8v10.5.2-072v11.0.0-641+2 more2019-05-03
CVE-2019-1816 [HIGH] CWE-20 CVE-2019-1816: A vulnerability in the log subscription subsystem of the Cisco Web Security Appliance (WSA) could al
A vulnerability in the log subscription subsystem of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. The vulnerability is due to insufficient validation of user-supplied input on the web and command-line interface. An attacker could exploit this vulnerability
nvd
CVE-2019-1817HIGHCVSS 7.5v11.5.1-fcs-115v11.5.1-fcs-124+2 more2019-05-03
CVE-2019-1817 [HIGH] CWE-20 CVE-2019-1817: A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appl
A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper validation of HTTP and HTTPS requests. An attacker could exploit this vulnerability by sending a
nvd
CVE-2019-1672MEDIUMCVSS 5.8v10.1.0-204v10.5.2-072+1 more2019-02-08
CVE-2019-1672 [MEDIUM] CWE-400 CVE-2019-1672: A vulnerability in the Decryption Policy Default Action functionality of the Cisco Web Security Appl
A vulnerability in the Decryption Policy Default Action functionality of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured drop policy and allow traffic onto the network that should have been denied. The vulnerability is due to the incorrect handling of SSL-encrypted traffic when Decrypt for
nvd
CVE-2018-0410HIGHCVSS 8.6v9.1.1-074v9.1.2-010+8 more2018-08-15
CVE-2018-0410 [HIGH] CWE-400 CVE-2018-0410: A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appl
A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliances could allow an unauthenticated, remote attacker to exhaust system memory and cause a denial of service (DoS) condition on an affected system. The vulnerability exists because the affected software improperly manages memory resources for TCP connect
nvd
CVE-2018-0428MEDIUMCVSS 6.7v11.0.0-fcs-250v11.5.0-fcs-000+2 more2018-08-15
CVE-2018-0428 [MEDIUM] CWE-284 CVE-2018-0428: A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allo
A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate with valid administrator credentials. The vulnerability is due to improper implementation of access controls. An attacker could exploit this vulnerability b
nvd
CVE-2018-0406MEDIUMCVSS 6.1v10.1.2-003v10.5.1-269+1 more2018-08-01
CVE-2018-0406 [MEDIUM] CWE-79 CVE-2018-0406: A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could al
A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a reflected or Document Object Model based (DOM-based) cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficie
nvd
1 / 3Next →