7.2
CVE-2024-20429
- EPSS 0.08%
- Published 17.07.2024 17:15:14
- Last modified 08.08.2025 01:56:39
- Source psirt@cisco.com
- Teams watchlist Login
- Open Login
A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary system commands on an affected device. This vulnerability is due to insufficient input validation in certain portions of the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges. To successfully exploit this vulnerability, an attacker would need at least valid Operator credentials.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Data is provided by the National Vulnerability Database (NVD)
Cisco ≫ Asyncos Version11.0.3-238
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version11.1.0-069
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version11.1.0-128
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version11.1.0-131
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version12.0.0-419
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version12.1.0-071
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version12.1.0-087
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version12.1.0-089
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version12.5.0-066
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version12.5.3-041
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version12.5.4-041
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version13.0.0-392
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version13.0.5-007
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version13.5.1-277
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version13.5.4-038
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version14.0.0-698
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version14.2.0-620
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Asyncos Version14.2.1-020
Cisco ≫ Secure Email Gateway Virtual Appliance C100v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C300v Version-
Cisco ≫ Secure Email Gateway Virtual Appliance C600v Version-
Cisco ≫ Secure Email Gateway C195 Version-
Cisco ≫ Secure Email Gateway C395 Version-
Cisco ≫ Secure Email Gateway C695 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.08% | 0.238 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
psirt@cisco.com | 6.5 | 1.2 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
|
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.