CVE-2023-20028: Cisco Secure Email Gateway, Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance Cross-Site Scripting Vulnerabilities
Published Jun 28, 2023
·Updated
Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
15 affected components
Cisco Secure Email and Web Manager=14.0.0-418
Cisco Secure Email and Web Manager=14.0.1-033
Cisco Secure Email and Web Manager=14.0.1-053
Cisco Secure Email and Web Manager=15.0.0-050
Cisco Secure Email and Web Manager=15.0.0-256
Cisco Secure Email Gateway=14.0.0-418
Cisco Secure Email Gateway=14.0.1-033
Cisco Secure Email Gateway=14.0.1-053
Cisco Secure Email Gateway=15.0.0-050
Cisco Secure Email Gateway=15.0.0-256
Cisco Web Security Appliance=14.0.0-418
Cisco Web Security Appliance=14.0.1-033
Cisco Web Security Appliance=14.0.1-053
Cisco Web Security Appliance=15.0.0-050
Cisco Web Security Appliance=15.0.0-256
Event History
Jun 28, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness