PT-2023-3311 · Cisco · Cisco Secure Email Gateway+2
Roberto Petrillo
·
Published
2023-06-21
·
Updated
2023-07-07
·
CVE-2023-20028
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco AsyncOS Software for Cisco Secure Email and Web Manager versions not specified
Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA) versions not specified
Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA) versions not specified
Description
The issue concerns multiple vulnerabilities in the web-based management interface of the mentioned Cisco products. These vulnerabilities could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerabilities exist due to inadequate protection of the web page structure.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Asyncos
Cisco Secure Email Gateway
Cisco Secure Web Appliance