Cisco
Cisco WEB Security Appliance: vulnerabilidades y CVE
Cisco WEB Security Appliance tiene 65 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE65
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-20120 | Media (6.1) | 0.47% | — | 28 jun 2023 | Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco… |
| CVE-2023-20119 | Media (6.1) | 0.51% | — | 28 jun 2023 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, formerly known as Content Security Management Appliance (SMA) could allow an unauthenticated,… |
| CVE-2023-20028 | Media (5.4) | 0.47% | — | 28 jun 2023 | Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco… |
| CVE-2023-20032 | Crítica (9.8) | 29% | — | 1 mar 2023 | On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and… |
| CVE-2022-20784 | Media (5.3) | 0.93% | — | 6 abr 2022 | A vulnerability in the Web-Based Reputation Score (WBRS) engine of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass established web request policies… |
| CVE-2021-1359 | Alta (8.8) | 1.9% | — | 8 jul 2021 | A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection and elevate privileges to root. This… |
| CVE-2021-1566 | Alta (7.4) | 0.67% | — | 16 jun 2021 | A vulnerability in the Cisco Advanced Malware Protection (AMP) for Endpoints integration of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco Web Security Appliance (WSA) could allow an unauthenticated,… |
| CVE-2021-1516 | Media (6.5) | 1.0% | — | 6 may 2021 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA), Cisco Email Security Appliance (ESA), and Cisco Web Security Appliance (WSA) could… |
| CVE-2021-1490 | Media (6.1) | 0.70% | — | 6 may 2021 | A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user… |
| CVE-2021-1129 | Media (5.3) | 1.1% | — | 20 ene 2021 | A vulnerability in the authentication for the general purpose APIs implementation of Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could… |
| CVE-2020-3117 | Media (4.7) | 0.93% | — | 23 sept 2020 | A vulnerability in the API Framework of Cisco AsyncOS for Cisco Web Security Appliance (WSA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to inject crafted HTTP… |
| CVE-2019-15969 | Media (6.1) | 0.80% | — | 23 sept 2020 | A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface… |
| CVE-2020-3164 | Media (5.3) | 1.3% | — | 4 mar 2020 | A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Security Management Appliance (SMA) could allow an… |
| CVE-2019-15956 | Alta (8.8) | 0.98% | — | 26 nov 2019 | A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform an unauthorized system reset on an affected… |
| CVE-2019-1886 | Alta (8.6) | 1.3% | — | 4 jul 2019 | A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to… |
| CVE-2019-1884 | Media (6.5) | 1.5% | — | 4 jul 2019 | A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected… |
| CVE-2019-1817 | Alta (7.5) | 1.8% | — | 3 may 2019 | A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected… |
| CVE-2019-1816 | Alta (7.8) | 0.64% | — | 3 may 2019 | A vulnerability in the log subscription subsystem of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. The vulnerability is… |
| CVE-2019-1672 | Media (5.8) | 1.6% | — | 8 feb 2019 | A vulnerability in the Decryption Policy Default Action functionality of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured drop policy and allow traffic onto… |
| CVE-2018-0428 | Media (6.7) | 0.44% | — | 15 ago 2018 | A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate with valid… |
| CVE-2018-0410 | Alta (8.6) | 4.1% | — | 15 ago 2018 | A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliances could allow an unauthenticated, remote attacker to exhaust system memory and cause a denial of service (DoS)… |
| CVE-2018-0406 | Media (6.1) | 1.8% | — | 1 ago 2018 | A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a reflected or Document Object Model based (DOM-based) cross-site… |
| CVE-2018-0366 | Media (6.1) | 1.8% | — | 16 jul 2018 | A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the… |
| CVE-2018-0353 | Alta (7.5) | 3.8% | — | 7 jun 2018 | A vulnerability in traffic-monitoring functions in Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to circumvent Layer 4 Traffic Monitor (L4TM) functionality and bypass security… |
| CVE-2018-0093 | Media (6.1) | 1.2% | — | 18 ene 2018 | A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the… |
| CVE-2017-6783 | Media (4.3) | 1.3% | — | 17 ago 2017 | A vulnerability in SNMP polling for the Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to discover… |
| CVE-2017-6751 | Alta (7.5) | 2.0% | — | 25 jul 2017 | A vulnerability in the web proxy functionality of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to forward traffic from the web proxy interface of an affected device to the… |
| CVE-2017-6750 | Alta (7.5) | 2.7% | — | 25 jul 2017 | A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an unauthenticated, local attacker to log in to the device with the privileges of a limited user or an unauthenticated, remote attacker… |
| CVE-2017-6749 | Media (5.4) | 1.2% | — | 25 jul 2017 | A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the… |
| CVE-2017-6748 | Media (6.7) | 0.82% | — | 25 jul 2017 | A vulnerability in the CLI parser of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. The attacker must authenticate with… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.