QID 316974

Date Published: 2021-05-26

QID 316974: Cisco Content Security Management Appliance, Email Security Appliance, Web Security Appliance Information Disclosure Vulnerability(cisco-sa-esa-wsa-sma-info-gY2AEz2H)

A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA),
Cisco Email Security Appliance (ESA), and Cisco Web Security Appliance (WSA) could allow an authenticated,
remote attacker to access sensitive information on an affected device.

Affected Products
Cisco Content SMA, ESA, and WSA releases that were running Cisco AsyncOS Software releases earlier than 14.0.

QID Detection Logic (Authenticated):
The check matches Cisco ASA version retrieved using "show version" command.

A successful exploit could allow the attacker to obtain some of the passwords that are configured throughout the interface.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution

    Customers are advised to refer to cisco-sa-esa-wsa-sma-info-RHp44vAC for more information.

    CVEs related to QID 316974

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-esa-wsa-sma-info-RHp44vAC URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-wsa-sma-info-RHp44vAC