CWE
89
Advisory Published

cisco-sa-esasmawsa-vulns-YRuSW5mD: Cisco Email Security Appliance, Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance Next Generation Management Vulnerabilities

First published: Wed Nov 02 2022(Updated: )

Multiple vulnerabilities in the next-generation UI management interface for Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an attacker to elevate privileges or to conduct a SQL injection attack and obtain root privileges. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esasmawsa-vulns-YRuSW5mD Attention: Simplifying the Cisco portfolio includes the renaming of security products under one brand: Cisco Secure. For more information, see Meet Cisco Secure.

Credit: an independent security researcher SSD Secure Disclosure for reporting these vulnerabilities

Affected SoftwareAffected VersionHow to fix
Cisco AsyncOS=14.3<14.3.0-0201>=13.0=13.5=14.0<=14.2<14.2.1-015
14.3.0-0201
14.2.1-015
Cisco AsyncOS=14.3<14.3.0-1151>=12.0=12.5=12.8=13.0=13.6=13.8=14.0=14.1<=14.2<14.2.0-217
14.3.0-1151
14.2.0-217
Cisco AsyncOS=14.5<14.5.1 (Nov 2022)=14.0<14.0.4 (Jan 2023)>=11.8=12.0<=12.5<12.5.5-004
14.5.1 (Nov 2022)
14.0.4 (Jan 2023)
12.5.5-004

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Child vulnerabilities

(Contains the following vulnerabilities)

Frequently Asked Questions

  • What is the vulnerability ID for the Cisco Email Security Appliance?

    The vulnerability ID for the Cisco Email Security Appliance is cisco-sa-esasmawsa-vulns-YRuSW5mD.

  • What is the severity of the Cisco Email Security Appliance vulnerability?

    The severity of the Cisco Email Security Appliance vulnerability is medium with a CVSS score of 5.4.

  • Which software versions are affected by the Cisco Email Security Appliance vulnerability?

    The Cisco Email Security Appliance vulnerability affects certain versions of Cisco AsyncOS, including 14.3.0-0201 and 14.2.1-015.

  • How can an attacker exploit the Cisco Email Security Appliance vulnerability?

    An attacker can exploit the Cisco Email Security Appliance vulnerability to elevate privileges or conduct a SQL injection attack.

  • Where can I find more information about the Cisco Email Security Appliance vulnerability?

    You can find more information about the Cisco Email Security Appliance vulnerability in the Cisco Security Advisory at: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esasmawsa-vulns-YRuSW5mD

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203