Vulnerabilities > Cisco > Email Security Appliance > 14.3.0.023

DATE CVE VULNERABILITY TITLE RISK
2023-03-01 CVE-2023-20009 Unrestricted Upload of File with Dangerous Type vulnerability in Cisco products
A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow an authenticated remote attacker and or authenticated local attacker to escalate their privilege level and gain root access.
network
low complexity
cisco CWE-434
7.2
2023-03-01 CVE-2023-20075 OS Command Injection vulnerability in Cisco Email Security Appliance
Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary commands. These vulnerability is due to improper input validation in the CLI.
local
low complexity
cisco CWE-78
6.7