CVE-2016-1423: XSS
A vulnerability in the display of email messages in the Messages in Quarantine (MIQ) view in Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a user to click a malicious link in the MIQ view. The malicious link could be used to facilitate a cross-site scripting (XSS) or HTML injection attack. More Information: CSCuz02235. Known Affected Releases: 8.0.2-069. Known Fixed Releases: 9.1.1-038 9.7.2-047.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1423?
The severity of CVE-2016-1423 is classified as high due to its potential for remote exploitation.
How do I fix CVE-2016-1423?
To fix CVE-2016-1423, update the Cisco Email Security Appliance to a patched version provided by Cisco.
Which versions of Cisco Email Security Appliance are affected by CVE-2016-1423?
CVE-2016-1423 affects versions 8.9.0, 8.9.1-000, 8.9.2-032, and various versions of 9.0.0 and 9.1.0.
Can CVE-2016-1423 be exploited remotely?
Yes, CVE-2016-1423 can be exploited by an unauthenticated remote attacker.
What types of attacks can be executed using CVE-2016-1423?
Exploitation of CVE-2016-1423 can lead to phishing attacks, where users may be tricked into clicking malicious links.