Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cisco Cisco Email Security Appliance and Content Security Management Appliance Information Disclosure Vulnerability
Vulnerability Description
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability exists because confidential information is being included in HTTP requests that are exchanged between the user and the device. An attacker could exploit this vulnerability by looking at the raw HTTP requests that are sent to the interface. A successful exploit could allow the attacker to obtain some of the passwords that are configured throughout the interface.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
通过发送数据的信息暴露
Vulnerability Title
Cisco ESA/CSMA 安全漏洞
Vulnerability Description
Cisco ESA/CSMA是美国思科(Cisco)公司的一个应用软件。提供电子邮件安全和内容安全管理防护。 Cisco ESA/CSMA 存在安全漏洞,攻击者可利用该漏洞可以通过基于web的管理接口绕过对数据的访问限制,以获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A