Cisco
Cisco Email Security Appliance: vulnerabilidades y CVE
Cisco Email Security Appliance tiene 50 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE50
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-3548 | Alta (7.5) | 0.84% | — | 18 nov 2024 | A vulnerability in the Transport Layer Security (TLS) protocol implementation of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause high… |
| CVE-2023-20075 | Media (6.7) | 0.45% | — | 1 mar 2023 | Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary commands. These vulnerability is due to improper input validation in the CLI. An attacker could… |
| CVE-2023-20009 | Alta (7.2) | 1.3% | — | 1 mar 2023 | A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow an authenticated remote attacker and or authenticated local attacker… |
| CVE-2022-20960 | Alta (7.5) | 0.83% | — | 4 nov 2022 | A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is… |
| CVE-2022-20798 | Crítica (9.8) | 1.5% | — | 15 jun 2022 | A vulnerability in the external authentication functionality of Cisco Secure Email and Web Manager, formerly known as Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an… |
| CVE-2022-20664 | Alta (7.7) | 1.0% | — | 15 jun 2022 | A vulnerability in the web management interface of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an authenticated, remote… |
| CVE-2021-1566 | Alta (7.4) | 0.67% | — | 16 jun 2021 | A vulnerability in the Cisco Advanced Malware Protection (AMP) for Endpoints integration of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco Web Security Appliance (WSA) could allow an unauthenticated,… |
| CVE-2021-1516 | Media (6.5) | 1.0% | — | 6 may 2021 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA), Cisco Email Security Appliance (ESA), and Cisco Web Security Appliance (WSA) could… |
| CVE-2021-1129 | Media (5.3) | 1.1% | — | 20 ene 2021 | A vulnerability in the authentication for the general purpose APIs implementation of Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could… |
| CVE-2020-3137 | Media (6.1) | 0.84% | — | 23 sept 2020 | A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the… |
| CVE-2020-3133 | Alta (7.5) | 1.4% | — | 23 sept 2020 | A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured filters on the device. The… |
| CVE-2019-1983 | Media (5.3) | 1.9% | — | 23 sept 2020 | A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote… |
| CVE-2019-1947 | Alta (8.6) | 1.9% | — | 23 sept 2020 | A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause the CPU utilization to increase to 100… |
| CVE-2020-3447 | Media (6.5) | 0.74% | — | 17 ago 2020 | A vulnerability in the CLI of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to access… |
| CVE-2020-3370 | Media (5.8) | 1.3% | — | 16 jul 2020 | A vulnerability in URL filtering of Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to bypass URL filtering on an affected device. The vulnerability is due to… |
| CVE-2020-3181 | Media (6.5) | 1.6% | — | 4 mar 2020 | A vulnerability in the malware detection functionality in Cisco Advanced Malware Protection (AMP) in Cisco AsyncOS Software for Cisco Email Security Appliances (ESAs) could allow an unauthenticated remote attacker to… |
| CVE-2020-3164 | Media (5.3) | 1.3% | — | 4 mar 2020 | A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Security Management Appliance (SMA) could allow an… |
| CVE-2020-3132 | Media (5.9) | 1.5% | — | 19 feb 2020 | A vulnerability in the email message scanning feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a temporary denial of service (DoS)… |
| CVE-2020-3134 | Media (6.5) | 1.1% | — | 26 ene 2020 | A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an… |
| CVE-2019-1933 | Alta (7.4) | 1.2% | — | 6 jul 2019 | A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured filters on the device. The… |
| CVE-2019-1921 | Alta (7.5) | 1.4% | — | 6 jul 2019 | A vulnerability in the attachment scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The… |
| CVE-2019-1905 | Media (5.8) | 1.4% | — | 20 jun 2019 | A vulnerability in the GZIP decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The… |
| CVE-2019-1844 | Media (5.3) | 1.7% | — | 3 may 2019 | A vulnerability in certain attachment detection mechanisms of the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of an affected device. The… |
| CVE-2019-1831 | Media (5.3) | 1.6% | — | 18 abr 2019 | A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The… |
| CVE-2018-0447 | Media (5.3) | 2.3% | — | 5 oct 2018 | A vulnerability in the anti-spam protection mechanisms of Cisco AsyncOS Software for the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass certain content filters on an… |
| CVE-2018-0419 | Alta (7.5) | 2.8% | — | 15 ago 2018 | A vulnerability in certain attachment detection mechanisms of Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of an affected system. The… |
| CVE-2017-6783 | Media (4.3) | 1.3% | — | 17 ago 2017 | A vulnerability in SNMP polling for the Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to discover… |
| CVE-2017-6661 | Media (6.1) | 1.2% | — | 13 jun 2017 | A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site… |
| CVE-2017-3800 | Media (5.8) | 1.5% | — | 26 ene 2017 | A vulnerability in the content scanning engine of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured message or content filters on the… |
| CVE-2016-9202 | Media (6.1) | 1.3% | — | 14 dic 2016 | A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) Switches could allow an unauthenticated, remote attacker to conduct a persistent cross-site scripting (XSS) attack against a… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.