QID 317341
Date Published: 2023-08-09
QID 317341: Cisco Secure Web Appliance Cross-Site Scripting (XSS) Vulnerability (cisco-sa-esa-sma-wsa-xss-cP9DuEmq)
Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
Affected Products
Cisco Web Security Appliance 14.5 and earlier versions
Cisco Web Security Appliance 15.0 prior to 15.0.0-332
The QID checks for the Vulnerable version of Cisco WSA in the response of "version" command.
Cisco Secure Web Appliance could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.
Solution
Customers are advised to refer to cisco-sa-esa-sma-wsa-xss-cP9DuEmq for more information.
Vendor References
- cisco-sa-esa-sma-wsa-xss-cP9DuEmq -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-xss-cP9DuEmq
CVEs related to QID 317341
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-esa-sma-wsa-xss-cP9DuEmq |
|