Vulnerabilities > Cisco > Ironport WEB Security Appliance > 7.5

DATE CVE VULNERABILITY TITLE RISK
2020-01-15 CVE-2012-1326 Improper Input Validation vulnerability in Cisco Ironport web Security Appliance 7.5
Cisco IronPort Web Security Appliance up to and including 7.5 does not validate the basic constraints of the certificate authority which could lead to MITM attacks
network
high complexity
cisco CWE-20
7.4
2020-01-15 CVE-2012-0334 Improper Input Validation vulnerability in Cisco Ironport web Security Appliance 7.5
Cisco IronPort Web Security Appliance AsyncOS software prior to 7.5 has a SSL Certificate Caching vulnerability which could allow man-in-the-middle attacks
high complexity
cisco CWE-20
6.4