Vulnerabilities > Cisco > Content Security Management Appliance > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-05-06 CVE-2021-1447 Improper Privilege Management vulnerability in Cisco Content Security Management Appliance
A vulnerability in the user account management system of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an authenticated, local attacker to elevate their privileges to root.
local
low complexity
cisco CWE-269
6.7
2021-05-06 CVE-2021-1516 Information Exposure Through Source Code vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA), Cisco Email Security Appliance (ESA), and Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to access sensitive information on an affected device.
network
low complexity
cisco CWE-540
6.5
2021-01-20 CVE-2021-1129 Information Exposure Through Sent Data vulnerability in Cisco products
A vulnerability in the authentication for the general purpose APIs implementation of Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to access general system information and certain configuration information from an affected device.
network
low complexity
cisco CWE-201
5.3
2020-09-23 CVE-2019-1983 Improper Input Validation vulnerability in Cisco Asyncos and Content Security Management Appliance
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause repeated crashes in some internal processes that are running on the affected devices, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
5.3
2020-09-23 CVE-2020-3117 Unspecified vulnerability in Cisco products
A vulnerability in the API Framework of Cisco AsyncOS for Cisco Web Security Appliance (WSA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to inject crafted HTTP headers in the web server's response.
network
low complexity
cisco
4.7
2020-08-17 CVE-2020-3447 Information Exposure Through Log Files vulnerability in Cisco products
A vulnerability in the CLI of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to access sensitive information on an affected device.
network
low complexity
cisco CWE-532
6.5
2020-05-06 CVE-2020-3178 Open Redirect vulnerability in Cisco Content Security Management Appliance
Multiple vulnerabilities in the web-based GUI of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.
network
low complexity
cisco CWE-601
6.1
2020-03-04 CVE-2020-3164 Improper Input Validation vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated remote attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
5.3
2019-09-05 CVE-2019-12635 Incorrect Permission Assignment for Critical Resource vulnerability in Cisco Content Security Management Appliance
A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software could allow an authenticated, remote attacker to gain out-of-scope access to email.
network
low complexity
cisco CWE-732
4.3
2018-11-08 CVE-2018-15393 Cross-site Scripting vulnerability in Cisco Content Security Management Appliance
A vulnerability in the web-based management interface of Cisco Content Security Management Appliance (SMA) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface.
network
low complexity
cisco CWE-79
6.1