Vulnerabilities > Cisco > Asyncos > 14.0.3.014

DATE CVE VULNERABILITY TITLE RISK
2023-08-03 CVE-2023-20215 Unspecified vulnerability in Cisco Asyncos
A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass a configured rule, allowing traffic onto a network that should have been blocked. This vulnerability is due to improper detection of malicious traffic when the traffic is encoded with a specific content format.
network
low complexity
cisco
5.3
2023-03-01 CVE-2022-20952 Unspecified vulnerability in Cisco Asyncos
A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an unauthenticated, remote attacker to bypass a configured rule, thereby allowing traffic onto a network that should have been blocked. This vulnerability exists because malformed, encoded traffic is not properly detected.
network
low complexity
cisco
5.3
2022-11-04 CVE-2022-20867 SQL Injection vulnerability in Cisco Asyncos
A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct SQL injection attacks as root on an affected system.
network
low complexity
cisco CWE-89
6.5
2022-11-04 CVE-2022-20868 Use of Hard-coded Credentials vulnerability in Cisco Asyncos
A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attacker to elevate privileges on an affected system.
network
low complexity
cisco CWE-798
8.8
2022-11-04 CVE-2022-20942 Incorrect Authorization vulnerability in Cisco Asyncos
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to retrieve sensitive information from an affected device, including user credentials. This vulnerability is due to weak enforcement of back-end authorization checks.
network
low complexity
cisco CWE-863
6.5
2022-04-06 CVE-2022-20675 Unspecified vulnerability in Cisco Asyncos
A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Secure Email and Web Manager, formerly Security Management Appliance, could allow an unauthenticated, remote attacker to crash the Simple Network Management Protocol (SNMP) service, resulting in a denial of service (DoS) condition.
network
low complexity
cisco
5.3
2022-04-06 CVE-2022-20781 Cross-site Scripting vulnerability in Cisco Asyncos
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device.
network
low complexity
cisco CWE-79
5.4