PT-2020-4226 · Cisco · Cisco Content Security Management Appliance+2

Published

2020-08-05

·

Updated

2020-08-20

·

CVE-2020-3447

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Cisco AsyncOS for Cisco Email Security Appliance and Cisco AsyncOS for Cisco Content Security Management Appliance (affected versions not specified)
Description: The issue is related to insufficient protection of registration data in the command-line interface of Cisco AsyncOS. It could allow a remote attacker to gain unauthorized access to sensitive information. The vulnerability is due to excessive verbosity in certain log subscriptions, which could allow an attacker to obtain sensitive log data, including user credentials, by accessing specific log files on an affected device. The attacker would need to have valid credentials at the operator level or higher to exploit this vulnerability.
Recommendations: For Cisco AsyncOS for Cisco Email Security Appliance and Cisco AsyncOS for Cisco Content Security Management Appliance, consider restricting access to log files and sensitive information to minimize the risk of exploitation. As a temporary workaround, consider disabling access to specific log subscriptions that may contain sensitive information until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04666
CVE-2020-3447

Affected Products

Cisco Asyncos
Cisco Content Security Management Appliance
Cisco Email Security Appliance