CVE-2023-20120: Cisco Secure Email Gateway, Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance Cross-Site Scripting Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-20120?
The severity of CVE-2023-20120 is medium.
Which software versions are affected by CVE-2023-20120?
Cisco Secure Email and Web Manager versions 14.0.0-418, 14.0.1-033, 14.0.1-053, 15.0.0-050, and 15.0.0-256; Cisco Secure Email Gateway versions 14.0.0-418, 14.0.1-033, 14.0.1-053, 15.0.0-050, and 15.0.0-256; Cisco Web Security Appliance versions 14.0.0-418, 14.0.1-033, 14.0.1-053, 15.0.0-050, and 15.0.0-256 are affected by CVE-2023-20120.
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-20120?
The CWE ID for CVE-2023-20120 is CWE-79.
How can I fix CVE-2023-20120?
Apply the necessary updates or patches provided by Cisco to fix CVE-2023-20120.
Where can I find more information about CVE-2023-20120?
You can find more information about CVE-2023-20120 on the Cisco Security Advisory page: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-xss-cP9DuEmq