Vulnerabilities > Cisco > Asyncos > 7.6.2

DATE CVE VULNERABILITY TITLE RISK
2023-08-04 CVE-2020-26082 Unspecified vulnerability in Cisco Asyncos
A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass content filters that are configured on an affected device. The vulnerability is due to improper handling of password-protected zip files.
network
low complexity
cisco
5.3
2022-11-04 CVE-2022-20942 Incorrect Authorization vulnerability in Cisco Asyncos
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to retrieve sensitive information from an affected device, including user credentials. This vulnerability is due to weak enforcement of back-end authorization checks.
network
low complexity
cisco CWE-863
6.5
2022-04-06 CVE-2022-20781 Cross-site Scripting vulnerability in Cisco Asyncos
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device.
network
low complexity
cisco CWE-79
5.4
2022-02-17 CVE-2022-20653 Unspecified vulnerability in Cisco Asyncos
A vulnerability in the DNS-based Authentication of Named Entities (DANE) email verification component of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco
7.5
2021-11-04 CVE-2021-34741 Allocation of Resources Without Limits or Throttling vulnerability in Cisco Asyncos
A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack against an affected device.
network
low complexity
cisco CWE-770
7.5
2021-10-06 CVE-2021-1534 Unspecified vulnerability in Cisco Asyncos
A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device.
network
low complexity
cisco
5.3
2021-06-16 CVE-2021-1566 Improper Certificate Validation vulnerability in Cisco Asyncos and Email Security Appliance
A vulnerability in the Cisco Advanced Malware Protection (AMP) for Endpoints integration of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to intercept traffic between an affected device and the AMP servers.
network
high complexity
cisco CWE-295
7.4
2020-11-18 CVE-2020-3367 OS Command Injection vulnerability in Cisco Asyncos
A vulnerability in the log subscription subsystem of Cisco AsyncOS for the Cisco Secure Web Appliance (formerly Web Security Appliance) could allow an authenticated, local attacker to perform command injection and elevate privileges to root.
local
low complexity
cisco CWE-78
7.2
2020-10-08 CVE-2020-3568 Improper Input Validation vulnerability in Cisco Asyncos
A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device.
network
low complexity
cisco CWE-20
5.8
2020-09-04 CVE-2020-3547 Insufficiently Protected Credentials vulnerability in Cisco Asyncos
A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to access sensitive information on an affected device.
network
low complexity
cisco CWE-522
6.5