QID 317294

QID 317294: Cisco Email Security Appliance (ESA) Command Injection Vulnerability (cisco-sa-esa-sma-privesc-9DVkFpJ8)

A vulnerability in the CLI of Cisco ESA could allow an authenticated, local attacker to execute arbitrary commands on an affected device.

Affected Products
12.5 Prior to 12.5.4-041
13.0 Prior to 13.0.5-007
13.5 Prior to 13.5.4-038
14.0 Prior to 14.2.1-020
14.3 Prior to 14.3.0-032

QID Detection Logic (Authenticated):
The check matches Cisco ESA OS version retrieved via Unix Auth using "version" command.

To successfully exploit this vulnerability, an attacker must have valid user credentials with Operator-level privileges or higher.

  • CVSS V3 rated as High - 6 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution

    Customers are advised to refer to cisco-sa-esa-sma-privesc-9DVkFpJ8 for more information.

    CVEs related to QID 317294

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-esa-sma-privesc-9DVkFpJ8 URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-privesc-9DVkFpJ8