VendorsCiscoemail_security_applianceall versions
Vulnerabilities

Cisco Email Security Appliance

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

57CVEs
CVE-2019-1831
Cisco Email Security Appliance Content Filter Bypass Vulnerability
Published 2019-04-18 · Modified
5.8EPSS 0.016
CVE-2017-3800
A vulnerability in the content scanning engine of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured message or content filters on the device. Affected Products: This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for Cisco Email Security Appliances, both virtual and hardware appliances, if the software is configured to apply a message filter or content filter to incoming email attachments. The vulnerability is not limited to any specific rules or actions for a message filter or content filter. More Information: CSCuz16076. Known Affected Releases: 9.7.1-066 9.7.1-HP2-207 9.8.5-085. Known Fixed Releases: 10.0.1-083 10.0.1-087.
Published 2017-01-26 · Modified
5.8EPSS 0.015
CVE-2020-3368
Cisco Email Security Appliance URL Filtering Bypass Vulnerability
Published 2020-06-18 · Modified
5.8EPSS 0.014
CVE-2019-1905
Cisco Email Security Appliance GZIP Content Filter Bypass Vulnerability
Published 2019-06-20 · Modified
5.8EPSS 0.014
CVE-2020-3370
Cisco Content Security Management Appliance Filter Bypass Vulnerability
Published 2020-07-16 · Modified
5.8EPSS 0.013
CVE-2018-0447
Cisco Email Security Appliance URL Filtering Bypass Vulnerability
Published 2018-10-05 · Modified
5.3EPSS 0.023
CVE-2019-1844
Cisco Email Security Appliance Filter Bypass Vulnerability
Published 2019-05-03 · Modified
5.3EPSS 0.017
CVE-2022-20675
Multiple Cisco Security Products Simple Network Management Protocol Service Denial of Service Vulnerability
Published 2022-04-06 · Modified
5.3EPSS 0.013
CVE-2020-3164
Cisco ESA, Cisco WSA, and Cisco SMA GUI Denial of Service Vulnerability
Published 2020-03-04 · Modified
5.3EPSS 0.013
CVE-2021-1129
Cisco Email Security Appliance, Cisco Content Security Management Appliance, and Cisco Web Security Appliance Information Disclosure Vulnerability
Published 2021-01-20 · Modified
5.3EPSS 0.011
CVE-2020-3546
Cisco Email Security Appliance Information Disclosure Vulnerability
Published 2020-09-04 · Modified
5.3EPSS 0.011
CVE-2022-20772
A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to the failure of the application or its environment to properly sanitize input values. An attacker could exploit this vulnerability by injecting malicious HTTP headers, controlling the response body, or splitting the response into multiple responses.
Published 2022-11-03 · Modified
5.3EPSS 0.006
CVE-2015-4184
The anti-spam scanner on Cisco Email Security Appliance (ESA) devices 3.3.1-09, 7.5.1-gpl-022, and 8.5.6-074 allows remote attackers to bypass intended e-mail restrictions via a malformed DNS SPF record, aka Bug IDs CSCuu35853 and CSCuu37733.
Published 2015-06-13 · Modified
5.0EPSS 0.035
CVE-2015-4236
Cisco AsyncOS on Email Security Appliance (ESA) devices with software 8.5.6-073, 8.5.6-074, and 9.0.0-461, when clustering is enabled, allows remote attackers to cause a denial of service (clustering and SSH outage) via a packet flood, aka Bug IDs CSCur13704 and CSCuq05636.
Published 2015-07-10 · Modified
4.3EPSS 0.024
CVE-2016-6465
A vulnerability in the content filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances and Cisco Web Security Appliances could allow an unauthenticated, remote attacker to bypass user filters that are configured for an affected device. Affected Products: This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for both virtual and hardware versions of the following Cisco products: Cisco Email Security Appliances (ESAs) that are configured to use message or content filters that scan incoming email attachments; Cisco Web Security Appliances (WSAs) that are configured to use services that scan accessed web content. More Information: CSCva90076, CSCvb06764. Known Affected Releases: 10.0.0-125 8.5.7-042 9.7.2-047.
Published 2016-12-14 · Modified
4.3EPSS 0.016
CVE-2017-6783
A vulnerability in SNMP polling for the Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to discover confidential information about the appliances that should be available only to an administrative user. The vulnerability occurs because the appliances do not protect confidential information at rest in response to Simple Network Management Protocol (SNMP) poll requests. An attacker could exploit this vulnerability by doing a crafted SNMP poll request to the targeted security appliance. An exploit could allow the attacker to discover confidential information that should be restricted, and the attacker could use this information to conduct additional reconnaissance. The attacker must know the configured SNMP community string to exploit this vulnerability. Cisco Bug IDs: CSCve26106, CSCve26202, CSCve26224. Known Affected Releases: 10.0.0-230 (Web Security Appliance), 9.7.2-065 (Email Security Appliance), and 10.1.0-037 (Content Security Management Appliance).
Published 2017-08-17 · Modified
4.3EPSS 0.013
CVE-2015-4288
The LDAP implementation on the Cisco Web Security Appliance (WSA) 8.5.0-000, Email Security Appliance (ESA) 8.5.7-042, and Content Security Management Appliance (SMA) 8.3.6-048 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate, aka Bug IDs CSCuo29561, CSCuv40466, and CSCuv40470.
Published 2015-07-29 · Modified
4.3EPSS 0.005
← Prev2 / 2