First published: Wed Nov 02 2022(Updated: )
Multiple vulnerabilities in the next-generation UI management interface for Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an attacker to elevate privileges or to conduct a SQL injection attack and obtain root privileges. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esasmawsa-vulns-YRuSW5mD Attention: Simplifying the Cisco portfolio includes the renaming of security products under one brand: Cisco Secure. For more information, see Meet Cisco Secure.
Credit: an independent security researcher SSD Secure Disclosure for reporting these vulnerabilities
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco AsyncOS | =14.3<14.3.0-0201>=13.0=13.5=14.0<=14.2<14.2.1-015 | 14.3.0-0201 14.2.1-015 |
Cisco AsyncOS | =14.3<14.3.0-1151>=12.0=12.5=12.8=13.0=13.6=13.8=14.0=14.1<=14.2<14.2.0-217 | 14.3.0-1151 14.2.0-217 |
Cisco AsyncOS | =14.5<14.5.1 (Nov 2022)=14.0<14.0.4 (Jan 2023)>=11.8=12.0<=12.5<12.5.5-004 | 14.5.1 (Nov 2022) 14.0.4 (Jan 2023) 12.5.5-004 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Cisco Email Security Appliance is cisco-sa-esasmawsa-vulns-YRuSW5mD.
The severity of the Cisco Email Security Appliance vulnerability is medium with a CVSS score of 5.4.
The Cisco Email Security Appliance vulnerability affects certain versions of Cisco AsyncOS, including 14.3.0-0201 and 14.2.1-015.
An attacker can exploit the Cisco Email Security Appliance vulnerability to elevate privileges or conduct a SQL injection attack.
You can find more information about the Cisco Email Security Appliance vulnerability in the Cisco Security Advisory at: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esasmawsa-vulns-YRuSW5mD