cbcvebase.

Cisco Web Security Appliance vulnerabilities

57 known vulnerabilities affecting cisco/web_security_appliance.

Total CVEs
57
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH26MEDIUM29

Vulnerabilities

Page 3 of 3
CVE-2021-1490P4MEDIUMCVSS 6.1fixed in 14.02021-05-06
CVE-2021-1490 [MEDIUM] CWE-79 CVE-2021-1490: A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Web Security Applia A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to improper validation of user-supplied input in the web-based manag
nvd
CVE-2023-20119P4MEDIUMCVSS 6.1v14.0.0-418v14.0.1-033+3 more2023-06-28
CVE-2023-20119 [MEDIUM] CWE-79 CVE-2023-20119: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, formerly known as Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient
nvd
CVE-2019-15969P4MEDIUMCVSS 6.1fixed in 11.8.02020-09-23
CVE-2019-15969 [MEDIUM] CWE-79 CVE-2019-15969: A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could al A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interfac
nvd
CVE-2020-3164P4MEDIUMCVSS 5.3≤ 12.0.1-2682020-03-04
CVE-2020-3164 [MEDIUM] CWE-20 CVE-2020-3164: A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appl A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated remote attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition. The vul
nvd
CVE-2016-1288P4MEDIUMCVSS 5.3v9.0.0-193v8.5.0-4972016-03-03
CVE-2016-1288 [MEDIUM] CWE-20 CVE-2016-1288: The HTTPS Proxy feature in Cisco AsyncOS before 8.5.3-051 and 9.x before 9.0.0-485 on Web Security A The HTTPS Proxy feature in Cisco AsyncOS before 8.5.3-051 and 9.x before 9.0.0-485 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (service outage) by leveraging certain intranet connectivity and sending a malformed HTTPS request, aka Bug ID CSCuu24840.
nvd
CVE-2023-20120P4MEDIUMCVSS 6.1v14.0.0-418v14.0.1-033+3 more2023-06-28
CVE-2023-20120 [MEDIUM] CWE-79 CVE-2023-20120: Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco S Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to conduct a cross-site scripting (XSS) a
nvd
CVE-2017-6749P4MEDIUMCVSS 5.4v10.0.0-232v10.0.0-233+9 more2017-07-25
CVE-2017-6749 [MEDIUM] CWE-79 CVE-2017-6749: A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could al A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. Affected Products: virtual and hardware versions of Cisco Web Security Appliance (WSA)
nvd
CVE-2015-6386P4MEDIUMCVSS 5.0v8.0.7-142v8.5.1-0212015-12-01
CVE-2015-6386 [MEDIUM] CWE-399 CVE-2015-6386: The passthrough FTP feature on Cisco Web Security Appliance (WSA) devices with software 8.0.7-142 an The passthrough FTP feature on Cisco Web Security Appliance (WSA) devices with software 8.0.7-142 and 8.5.1-021 allows remote attackers to cause a denial of service (CPU consumption) via FTP sessions in which the control connection is ended after data transfer, aka Bug ID CSCut94150.
nvd
CVE-2020-3117P4MEDIUMCVSS 4.7v11.8.0-382v12.0.1-2682020-09-23
CVE-2020-3117 [MEDIUM] CWE-113 CVE-2020-3117: A vulnerability in the API Framework of Cisco AsyncOS for Cisco Web Security Appliance (WSA) and Cis A vulnerability in the API Framework of Cisco AsyncOS for Cisco Web Security Appliance (WSA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to inject crafted HTTP headers in the web server's response. The vulnerability is due to insufficient validation of user input. An attacker could exploit this
nvd
CVE-2023-20028P4MEDIUMCVSS 5.4v14.0.0-418v14.0.1-033+3 more2023-06-28
CVE-2023-20028 [MEDIUM] CWE-79 CVE-2023-20028: Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco S Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to conduct a cross-site scripting (XSS) a
nvd
CVE-2016-1440P4MEDIUMCVSS 5.3v5.6.0-623v6.0.0-000+35 more2016-07-02
CVE-2016-1440 [MEDIUM] CWE-399 CVE-2016-1440: The proxy process on Cisco Web Security Appliance (WSA) devices through 9.1.0-070 allows remote atta The proxy process on Cisco Web Security Appliance (WSA) devices through 9.1.0-070 allows remote attackers to cause a denial of service (CPU consumption) by establishing an FTP session and then improperly terminating the control connection after a file transfer, aka Bug ID CSCuy43468.
nvd
CVE-2017-6783P4MEDIUMCVSS 4.3v10.0.0-2302017-08-17
CVE-2017-6783 [MEDIUM] CWE-200 CVE-2017-6783: A vulnerability in SNMP polling for the Cisco Web Security Appliance (WSA), Email Security Appliance A vulnerability in SNMP polling for the Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to discover confidential information about the appliances that should be available only to an administrative user. The vulnerability occurs because the
nvd
CVE-2015-4198P4MEDIUMCVSS 4.3v8.5.0-4972015-06-20
CVE-2015-4198 [MEDIUM] CWE-79 CVE-2015-4198: Cross-site scripting (XSS) vulnerability in the web framework on Cisco Web Security Appliance (WSA) Cross-site scripting (XSS) vulnerability in the web framework on Cisco Web Security Appliance (WSA) devices with software 8.5.0-497 allows remote attackers to inject arbitrary web script or HTML via an unspecified HTTP header, aka Bug ID CSCuu24409.
nvd
CVE-2015-0732P4MEDIUMCVSS 4.3v9.0.0-1932015-07-29
CVE-2015-0732 [MEDIUM] CWE-79 CVE-2015-0732: Cross-site scripting (XSS) vulnerability in Cisco AsyncOS on the Web Security Appliance (WSA) 9.0.0- Cross-site scripting (XSS) vulnerability in Cisco AsyncOS on the Web Security Appliance (WSA) 9.0.0-193; Email Security Appliance (ESA) 8.5.6-113, 9.1.0-032, 9.1.1-000, and 9.6.0-000; and Content Security Management Appliance (SMA) 9.1.0-033 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug IDs CSCuu37
nvd
CVE-2015-0738P4MEDIUMCVSS 4.3v8.5.0-4972015-05-17
CVE-2015-0738 [MEDIUM] CWE-79 CVE-2015-0738: Cross-site scripting (XSS) vulnerability in the Web Tracking Report page on Cisco Web Security Appli Cross-site scripting (XSS) vulnerability in the Web Tracking Report page on Cisco Web Security Appliance (WSA) devices 8.5.0-497 allows remote attackers to inject arbitrary web script or HTML via an unspecified field, aka Bug ID CSCuu16008.
nvd
CVE-2015-0698P4MEDIUMCVSS 4.3≤ 8.5.0-4972015-04-15
CVE-2015-0698 [MEDIUM] CWE-79 CVE-2015-0698: Multiple cross-site scripting (XSS) vulnerabilities in filter search forms in admin web pages on Cis Multiple cross-site scripting (XSS) vulnerabilities in filter search forms in admin web pages on Cisco Web Security Appliance (WSA) devices with software 8.5.0-497 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut39213.
nvd
CVE-2015-4288P4MEDIUMCVSS 4.3v8.5.0-0002015-07-29
CVE-2015-4288 [MEDIUM] CWE-310 CVE-2015-4288: The LDAP implementation on the Cisco Web Security Appliance (WSA) 8.5.0-000, Email Security Applianc The LDAP implementation on the Cisco Web Security Appliance (WSA) 8.5.0-000, Email Security Appliance (ESA) 8.5.7-042, and Content Security Management Appliance (SMA) 8.3.6-048 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate, aka B
nvd
Cisco Web Security Appliance vulnerabilities | cvebase