QID 317341

Date Published: 2023-08-09

QID 317341: Cisco Secure Web Appliance Cross-Site Scripting (XSS) Vulnerability (cisco-sa-esa-sma-wsa-xss-cP9DuEmq)

Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.

Affected Products
Cisco Web Security Appliance 14.5 and earlier versions
Cisco Web Security Appliance 15.0 prior to 15.0.0-332

The QID checks for the Vulnerable version of Cisco WSA in the response of "version" command.

Cisco Secure Web Appliance could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution

    Customers are advised to refer to cisco-sa-esa-sma-wsa-xss-cP9DuEmq for more information.

    CVEs related to QID 317341

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-esa-sma-wsa-xss-cP9DuEmq URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-xss-cP9DuEmq