6.5

CVE-2022-20942

A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to retrieve sensitive information from an affected device, including user credentials.

 This vulnerability is due to weak enforcement of back-end authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain confidential data that is stored on the affected device.

Data is provided by the National Vulnerability Database (NVD)
CiscoAsyncos Version < 14.2.1-015
   CiscoSecure Email Gateway Version-
CiscoAsyncos Version >= 14.3.0 < 14.3.0-023
   CiscoSecure Email Gateway Version-
CiscoAsyncos Version < 14.2.0-217
CiscoAsyncos Version >= 14.3.0 < 14.3.0-115
CiscoAsyncos Version < 12.0.5-011
   CiscoSecure Web Appliance Version-
CiscoAsyncos Version >= 12.5 < 12.5.4-005
   CiscoSecure Web Appliance Version-
CiscoAsyncos Version >= 14.0 < 14.0.2-012
   CiscoSecure Web Appliance Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.14% 0.34
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
psirt@cisco.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-359 Exposure of Private Personal Information to an Unauthorized Actor

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.