CVE-2022-20868
- EPSS 0.1%
- Published 04.11.2022 18:15:10
- Last modified 21.11.2024 06:43:43
A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attacker to elevate privileges on an affected system. The ...
CVE-2022-20867
- EPSS 0.05%
- Published 04.11.2022 18:15:10
- Last modified 21.11.2024 06:43:43
A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct SQL injection attacks as root on an affected system. The attack...
CVE-2022-20781
- EPSS 0.18%
- Published 06.04.2022 19:15:08
- Last modified 21.11.2024 06:43:32
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface...
CVE-2022-20675
- EPSS 1.27%
- Published 06.04.2022 19:15:08
- Last modified 21.11.2024 06:43:17
A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Secure Email and Web Manager, formerly Security Management Appliance, could allow an unauthenticated, remote attacker to crash ...
CVE-2022-20653
- EPSS 0.98%
- Published 17.02.2022 15:15:09
- Last modified 21.11.2024 06:43:14
A vulnerability in the DNS-based Authentication of Named Entities (DANE) email verification component of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS...
CVE-2021-34741
- EPSS 0.24%
- Published 04.11.2021 16:15:08
- Last modified 21.11.2024 06:11:05
A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack against an affected device. This vulnerabil...
CVE-2021-34698
- EPSS 0.52%
- Published 06.10.2021 20:15:08
- Last modified 21.11.2024 06:10:58
A vulnerability in the proxy service of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to exhaust system memory and cause a denial of service (DoS) condition on an affected device. This vulnerabil...
CVE-2021-1534
- EPSS 0.28%
- Published 06.10.2021 20:15:07
- Last modified 21.11.2024 05:44:34
A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. This vulnerability is...
- EPSS 1.26%
- Published 08.07.2021 19:15:08
- Last modified 21.11.2024 05:44:10
A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection and elevate privileges to root. This vulnerability is due to insufficie...
CVE-2021-1566
- EPSS 0.1%
- Published 16.06.2021 18:15:08
- Last modified 21.11.2024 05:44:38
A vulnerability in the Cisco Advanced Malware Protection (AMP) for Endpoints integration of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to intercept tra...