Vulnerabilities > Cisco > Asyncos > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-09-23 CVE-2019-1983 Improper Input Validation vulnerability in Cisco Asyncos and Content Security Management Appliance
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause repeated crashes in some internal processes that are running on the affected devices, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
5.3
2020-09-04 CVE-2020-3547 Insufficiently Protected Credentials vulnerability in Cisco Asyncos
A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to access sensitive information on an affected device.
network
low complexity
cisco CWE-522
6.5
2020-09-04 CVE-2020-3546 Improper Input Validation vulnerability in Cisco Asyncos
A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to access sensitive information on an affected device.
network
low complexity
cisco CWE-20
5.3
2020-06-18 CVE-2020-3368 Improper Input Validation vulnerability in Cisco Asyncos
A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device.
network
low complexity
cisco CWE-20
5.8
2019-07-04 CVE-2019-1884 Improper Input Validation vulnerability in Cisco Asyncos and web Security Appliance
A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
6.5
2018-03-08 CVE-2018-0087 Improper Authentication vulnerability in Cisco Asyncos 10.5.1296
A vulnerability in the FTP server of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to log in to the FTP server of the device without a valid password.
network
high complexity
cisco CWE-287
5.6
2017-11-30 CVE-2017-12353 Unspecified vulnerability in Cisco Asyncos
A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device.
network
low complexity
cisco
5.8
2017-11-16 CVE-2017-12303 Improperly Implemented Security Check for Standard vulnerability in Cisco Asyncos 10.1.1234/10.1.1235
A vulnerability in the Advanced Malware Protection (AMP) file filtering feature of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured AMP file filtering rule.
network
low complexity
cisco CWE-358
5.3
2017-09-07 CVE-2017-12218 Improper Input Validation vulnerability in Cisco Asyncos
A vulnerability in the malware detection functionality within Advanced Malware Protection (AMP) of Cisco AsyncOS Software for Cisco Email Security Appliances (ESAs) could allow an unauthenticated, remote attacker to cause an email attachment containing malware to be delivered to the end user.
network
low complexity
cisco CWE-20
5.8