cisco-sa-esa-url-bypass-WbMQqNJh: Cisco Email Security Appliance URL Filtering Bypass Vulnerability
On January 18, 2023, Cisco disclosed the following:A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-esa-url-bypass-WbMQqNJh?
The severity of the vulnerability cisco-sa-esa-url-bypass-WbMQqNJh is classified as high, as it allows attackers to bypass URL reputation filters.
How do I fix cisco-sa-esa-url-bypass-WbMQqNJh?
To fix the vulnerability cisco-sa-esa-url-bypass-WbMQqNJh, users should upgrade to the latest version of Cisco AsyncOS Software for the Email Security Appliance.
Who is affected by cisco-sa-esa-url-bypass-WbMQqNJh?
The vulnerability cisco-sa-esa-url-bypass-WbMQqNJh affects users of Cisco Email Security Appliance running vulnerable versions of Cisco AsyncOS Software.
What are the potential impacts of cisco-sa-esa-url-bypass-WbMQqNJh?
The potential impacts of cisco-sa-esa-url-bypass-WbMQqNJh include unauthorized access to malicious URLs, leading to phishing and malware incidents.
Is there a workaround for cisco-sa-esa-url-bypass-WbMQqNJh?
Currently, no official workarounds are provided for the cisco-sa-esa-url-bypass-WbMQqNJh vulnerability other than applying the security update.