6.5

CVE-2022-20942

A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to retrieve sensitive information from an affected device, including user credentials.

 This vulnerability is due to weak enforcement of back-end authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain confidential data that is stored on the affected device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Asyncos Version < 14.2.1-015
   Cisco ≫ Secure Email Gateway Version -
Cisco ≫ Asyncos Version >= 14.3.0 < 14.3.0-023
   Cisco ≫ Secure Email Gateway Version -
Cisco ≫ Asyncos Version < 14.2.0-217
   Cisco ≫ Secure Email And Web Manager Version -
Cisco ≫ Asyncos Version >= 14.3.0 < 14.3.0-115
   Cisco ≫ Secure Email And Web Manager Version -
Cisco ≫ Asyncos Version < 12.0.5-011
   Cisco ≫ Secure Web Appliance Version -
Cisco ≫ Asyncos Version >= 12.5 < 12.5.4-005
   Cisco ≫ Secure Web Appliance Version -
Cisco ≫ Asyncos Version >= 14.0 < 14.0.2-012
   Cisco ≫ Secure Web Appliance Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.92% 0.571
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Cisco PSIRT 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-359 Exposure of Private Personal Information to an Unauthorized Actor

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cnt-sec-infodiscl-BVKKnUG