PT-2022-6261 · Cisco · Cisco Asyncos Software For Cisco Email Security Appliance

Chen Farchi

+1

·

Published

2022-10-27

·

Updated

2024-03-22

·

CVE-2023-20057

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) (affected versions not specified)
Description A vulnerability in the URL filtering mechanism could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. This issue is due to improper processing of URLs. An attacker could exploit this by crafting a URL in a particular way, potentially allowing malicious URLs to pass through the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Special Elements Injection

Weakness Enumeration

Related Identifiers

BDU:2023-00676
CVE-2023-20057

Affected Products

Cisco Asyncos Software For Cisco Email Security Appliance