6.1
CVE-2024-20392
- EPSS 0.24%
- Published 15.05.2024 18:15:10
- Last modified 06.08.2025 16:48:40
- Source psirt@cisco.com
- Teams watchlist Login
- Open Login
A vulnerability in the web-based management API of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to insufficient input validation of some parameters that are passed to the web-based management API of the affected system. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to perform cross-site scripting (XSS) attacks, resulting in the execution of arbitrary script code in the browser of the targeted user, or could allow the attacker to access sensitive, browser-based information.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Data is provided by the National Vulnerability Database (NVD)
Cisco ≫ Asyncos Version11.0.3-238
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version11.1.0-069
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version11.1.0-128
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version12.0.0-419
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version12.1.0-071
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version12.1.0-087
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version12.1.0-089
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version12.5.0-066
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version12.5.3-041
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version12.5.4-041
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version13.0.0-392
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version13.0.5-007
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version13.5.1-277
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version13.5.4-038
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version14.0.0-698
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version14.2.0-620
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version14.2.1-020
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version14.3.0-032
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version15.0.0-104
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version15.0.1-030
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version15.5.0-048
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.24% | 0.465 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
psirt@cisco.com | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
The product receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.