Vulnerabilities > Cisco > Email Security Appliance > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-01-26 CVE-2020-3134 Improper Input Validation vulnerability in Cisco Email Security Appliance
A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
6.5
2019-06-20 CVE-2019-1905 Improper Input Validation vulnerability in Cisco Email Security Appliance 11.1.2/12.0.0
A vulnerability in the GZIP decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device.
network
low complexity
cisco CWE-20
5.8
2019-05-03 CVE-2019-1844 Improper Input Validation vulnerability in Cisco Email Security Appliance 11.1.0131
A vulnerability in certain attachment detection mechanisms of the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of an affected device.
network
low complexity
cisco CWE-20
5.3
2019-04-18 CVE-2019-1831 Improper Input Validation vulnerability in Cisco Email Security Appliance 11.1.2023/12.0.0208
A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device.
network
low complexity
cisco CWE-20
5.3
2018-10-05 CVE-2018-0447 Improper Input Validation vulnerability in Cisco Email Security Appliance
A vulnerability in the anti-spam protection mechanisms of Cisco AsyncOS Software for the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass certain content filters on an affected device.
network
low complexity
cisco CWE-20
5.3
2017-08-17 CVE-2017-6783 Information Exposure vulnerability in Cisco products
A vulnerability in SNMP polling for the Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to discover confidential information about the appliances that should be available only to an administrative user.
network
low complexity
cisco CWE-200
4.3
2017-06-13 CVE-2017-6661 Cross-site Scripting vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device, aka Message Tracking XSS.
network
low complexity
cisco CWE-79
6.1
2017-01-26 CVE-2017-3800 Improper Input Validation vulnerability in Cisco Email Security Appliance 9.7.1066/9.7.1Hp2207/9.8.5085
A vulnerability in the content scanning engine of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured message or content filters on the device.
network
low complexity
cisco CWE-20
5.8
2016-12-14 CVE-2016-9202 Cross-site Scripting vulnerability in Cisco Email Security Appliance
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) Switches could allow an unauthenticated, remote attacker to conduct a persistent cross-site scripting (XSS) attack against a user of the affected interface on an affected device.
network
low complexity
cisco CWE-79
6.1
2016-12-14 CVE-2016-6465 Improper Input Validation vulnerability in Cisco Email Security Appliance
A vulnerability in the content filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances and Cisco Web Security Appliances could allow an unauthenticated, remote attacker to bypass user filters that are configured for an affected device.
network
low complexity
cisco CWE-20
4.3