QID 317340

Date Published: 2023-08-09

QID 317340: Cisco Secure Email and Web Manager Multiple Cross-Site Scripting (XSS) Vulnerabilities (cisco-sa-esa-sma-wsa-xss-cP9DuEmq)

Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.

Affected Products
14.3 and prior versions of Cisco Secure Email and Web Manager
15.0 prior to Version 15.0.0-317 of Cisco Secure Email and Web Manager

QID Detection Logic (Authenticated):
The check matches Cisco Secure Email and Web Manager OS version retrieved via Unix Auth using "version" command.
Note: This QID only supports the hardware version of Cisco Secure Email and Web Manager

Successful exploitation could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution

    Customers are advised to refer to cisco-sa-esa-sma-wsa-xss-cP9DuEmq for more information.

    CVEs related to QID 317340

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-esa-sma-wsa-xss-cP9DuEmq URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-xss-cP9DuEmq