QID 317339

Date Published: 2023-08-10

QID 317339: Cisco Secure Email Gateway Cross-Site Scripting (XSS) Vulnerability (cisco-sa-esa-sma-wsa-xss-cP9DuEmq)

Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA) could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.

Affected Products
14.3 and prior versions of Secure Email Gateway
15.0 prior to Version 15.0.0-068

QID Detection Logic (Authenticated):
The check matches Cisco ESA OS version retrieved via Unix Auth using "version" command.
Note: This QID does not support Cisco Virtual ESA

Successful exploitation could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution

    Customers are advised to refer to cisco-sa-esa-sma-wsa-xss-cP9DuEmq for more information.

    CVEs related to QID 317339

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-esa-sma-wsa-xss-cP9DuEmq URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-xss-cP9DuEmq