PT-2022-5478 · Cisco · Cisco Secure Email/Web Manager+1
Published
2022-11-02
·
Updated
2024-01-25
·
CVE-2022-20772
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager (affected versions not specified)
Description
The issue is related to the failure of the application to properly handle CRLF sequences in HTTP headers, allowing an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This can be achieved by injecting malicious HTTP headers, controlling the response body, or splitting the response into multiple responses. The vulnerability is due to the failure to properly sanitize input values.
Recommendations
For Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager, consider disabling the handling of CRLF sequences in HTTP headers as a temporary workaround until a patch is available. Restrict access to the vulnerable components to minimize the risk of exploitation. Avoid using malicious HTTP headers in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Email Security Appliance
Cisco Secure Email/Web Manager