QID 317294
QID 317294: Cisco Email Security Appliance (ESA) Command Injection Vulnerability (cisco-sa-esa-sma-privesc-9DVkFpJ8)
A vulnerability in the CLI of Cisco ESA could allow an authenticated, local attacker to execute arbitrary commands on an affected device.
Affected Products
12.5 Prior to 12.5.4-041
13.0 Prior to 13.0.5-007
13.5 Prior to 13.5.4-038
14.0 Prior to 14.2.1-020
14.3 Prior to 14.3.0-032
QID Detection Logic (Authenticated):
The check matches Cisco ESA OS version retrieved via Unix Auth using "version" command.
To successfully exploit this vulnerability, an attacker must have valid user credentials with Operator-level privileges or higher.
Solution
Customers are advised to refer to cisco-sa-esa-sma-privesc-9DVkFpJ8 for more information.
Vendor References
- cisco-sa-esa-sma-privesc-9DVkFpJ8 -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-privesc-9DVkFpJ8
CVEs related to QID 317294
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-esa-sma-privesc-9DVkFpJ8 |
|