cve,link,title,description,vendor,products,score,severity,epss,cisa,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2021-1425,https://securityvulnerability.io/vulnerability/CVE-2021-1425,Cisco AsyncOS Software Vulnerability Could Allow Access to Sensitive Information,"A security vulnerability exists within the web-based management interface of Cisco AsyncOS Software for Content Security Management Appliances. This issue arises from sensitive information being transmitted in HTTP requests between the user and the device. An authenticated remote attacker could exploit this flaw by examining raw HTTP requests sent to the management interface, potentially leading to the unauthorized access of stored passwords and other confidential information. Cisco has addressed this concern with software updates, but no workarounds are available to mitigate the risk.",Cisco,Cisco Secure Email And Web Manager,4.3,MEDIUM,0.00044999999227002263,false,false,false,false,,false,false,2024-11-18T15:36:48.271Z,0 CVE-2024-20383,https://securityvulnerability.io/vulnerability/CVE-2024-20383,Cisco AsyncOS Software Vulnerability Could Lead to XSS Attacks,"A vulnerability in the Cisco Crosswork NSO CLI and the ConfD CLI could allow an authenticated, low-privileged, local attacker to elevate privileges to root on the underlying operating system. The vulnerability is due to an incorrect privilege assignment when specific CLI commands are used. An attacker could exploit this vulnerability by executing an affected CLI command. A successful exploit could allow the attacker to elevate privileges to root on the underlying operating system.",Cisco,Cisco Secure Email And Web Manager,4.8,MEDIUM,0.0004299999854993075,false,false,false,false,,false,false,2024-05-15T17:59:49.921Z,0 CVE-2024-20256,https://securityvulnerability.io/vulnerability/CVE-2024-20256,Cisco AsyncOS Software Vulnerability Could Lead to XSS Attacks,"A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Web Appliance could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.",Cisco,"Cisco Secure Web Appliance,Cisco Secure Email And Web Manager",4.8,MEDIUM,0.0004299999854993075,false,false,false,false,,false,false,2024-05-15T17:56:38.074Z,0 CVE-2024-20258,https://securityvulnerability.io/vulnerability/CVE-2024-20258,Cisco AsyncOS Software Vulnerability Could Lead to XSS Attacks,"A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.",Cisco,"Cisco Secure Email,Cisco Secure Email And Web Manager",6.1,MEDIUM,0.0004299999854993075,false,false,false,false,,false,false,2024-05-15T17:32:16.125Z,0 CVE-2023-20119,https://securityvulnerability.io/vulnerability/CVE-2023-20119,,"A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, formerly known as Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient user input validation. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.",Cisco,Cisco Secure Email and Web Manager,6.1,MEDIUM,0.0010000000474974513,false,false,false,false,,false,false,2023-06-28T00:00:00.000Z,0 CVE-2023-20009,https://securityvulnerability.io/vulnerability/CVE-2023-20009,Privilege Escalation in Cisco Secure Email Gateway and Manager,"A vulnerability exists within the Web UI and administrative CLI of Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA). This security flaw enables both authenticated local and remote attackers to escalate their privileges, potentially gaining root access on the device. The issue arises from the mishandling of specially crafted SNMP configuration files. To exploit this vulnerability, an attacker must have valid user credentials with operational privileges. Once authenticated, the attacker can upload a malicious SNMP configuration file that could allow for the execution of commands as root, thereby compromising the device's integrity.",Cisco,"Cisco Secure Email,Cisco Secure Email and Web Manager",7.2,HIGH,0.0016400000313296914,false,false,false,false,,false,false,2023-03-01T08:15:00.000Z,0 CVE-2022-20772,https://securityvulnerability.io/vulnerability/CVE-2022-20772,,"A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to the failure of the application or its environment to properly sanitize input values. An attacker could exploit this vulnerability by injecting malicious HTTP headers, controlling the response body, or splitting the response into multiple responses.",Cisco,"Cisco Secure Email,Cisco Secure Email And Web Manager",4.7,MEDIUM,0.0012100000167265534,false,false,false,true,,false,false,2022-11-04T18:15:00.000Z,0 CVE-2022-20868,https://securityvulnerability.io/vulnerability/CVE-2022-20868,,"A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attacker to elevate privileges on an affected system. The attacker needs valid credentials to exploit this vulnerability. This vulnerability is due to the use of a hardcoded value to encrypt a token used for certain APIs calls . An attacker could exploit this vulnerability by authenticating to the device and sending a crafted HTTP request. A successful exploit could allow the attacker to impersonate another valid user and execute commands with the privileges of that user account. ",Cisco,"Cisco Secure Web Appliance,Cisco Secure Email,Cisco Secure Email And Web Manager",4.7,MEDIUM,0.0033599999733269215,false,false,false,true,,false,false,2022-11-04T18:15:00.000Z,0 CVE-2022-20942,https://securityvulnerability.io/vulnerability/CVE-2022-20942,,"A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to retrieve sensitive information from an affected device, including user credentials. This vulnerability is due to weak enforcement of back-end authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain confidential data that is stored on the affected device.",Cisco,"Cisco Secure Web Appliance,Cisco Secure Email,Cisco Secure Email And Web Manager",6.5,MEDIUM,0.0011599999852478504,false,false,false,true,,false,false,2022-11-04T18:15:00.000Z,0 CVE-2022-20867,https://securityvulnerability.io/vulnerability/CVE-2022-20867,,"A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct SQL injection attacks as root on an affected system. The attacker must have the credentials of a high-privileged user account. This vulnerability is due to improper validation of user-submitted parameters. An attacker could exploit this vulnerability by authenticating to the application and sending malicious requests to an affected system. A successful exploit could allow the attacker to obtain data or modify data that is stored in the underlying database of the affected system. ",Cisco,"Cisco Secure Email,Cisco Secure Email And Web Manager",5.4,MEDIUM,0.0008399999933317304,false,false,false,true,,false,false,2022-11-04T18:15:00.000Z,0