PT-2020-3888 · Cisco · Cisco Content Security Management Appliance+1

Published

2020-07-15

·

Updated

2021-08-06

·

CVE-2020-3370

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Cisco Content Security Management Appliance (SMA) (affected versions not specified) Cisco Email Security Appliance (affected versions not specified)
Description: The issue is related to insufficient input validation in the URL filtering mechanism, allowing an unauthenticated, remote attacker to bypass URL filtering by sending a crafted, malicious HTTP request. A successful exploit could enable the attacker to redirect users to malicious sites.
Recommendations: For Cisco Content Security Management Appliance (SMA), update the URL filtering mechanism to properly validate input data. For Cisco Email Security Appliance, ensure that the URL filtering mechanism is configured to correctly handle and validate HTTP requests to prevent bypassing. As a temporary workaround, consider restricting access to sensitive areas of the network until a proper fix is applied.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04281
CVE-2020-3370

Affected Products

Cisco Content Security Management Appliance
Cisco Email Security Appliance