First published: Wed Jun 28 2023(Updated: )
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, formerly known as Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient user input validation. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Credit: ykramarz@cisco.com ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Secure Email and Web Manager | =14.0.0-418 | |
Cisco Secure Email and Web Manager | =14.0.1-033 | |
Cisco Secure Email and Web Manager | =14.0.1-053 | |
Cisco Secure Email and Web Manager | =15.0.0-050 | |
Cisco Secure Email and Web Manager | =15.0.0-256 | |
Cisco Secure Email Gateway | =14.0.0-418 | |
Cisco Secure Email Gateway | =14.0.1-033 | |
Cisco Secure Email Gateway | =14.0.1-053 | |
Cisco Secure Email Gateway | =15.0.0-050 | |
Cisco Secure Email Gateway | =15.0.0-256 | |
Cisco Web Security Appliance | =14.0.0-418 | |
Cisco Web Security Appliance | =14.0.1-033 | |
Cisco Web Security Appliance | =14.0.1-053 | |
Cisco Web Security Appliance | =15.0.0-050 | |
Cisco Web Security Appliance | =15.0.0-256 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-20119 is a vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, which could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack.
The affected software versions are Cisco Secure Email and Web Manager 14.0.0-418, 14.0.1-033, 14.0.1-053, 15.0.0-050, and 15.0.0-256.
The severity of CVE-2023-20119 is medium with a CVSS score of 6.1.
An unauthenticated, remote attacker can exploit CVE-2023-20119 by conducting a cross-site scripting (XSS) attack against a user of the affected software.
You can find more information about CVE-2023-20119 in the Cisco Security Advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-xss-cP9DuEmq.