cisco email_security_appliance 信息暴露

CVE编号

CVE-2022-20664

利用情况

暂无

补丁情况

N/A

披露时间

2022-06-16
漏洞描述
A vulnerability in the web management interface of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an authenticated, remote attacker to retrieve sensitive information from a Lightweight Directory Access Protocol (LDAP) external authentication server connected to an affected device. This vulnerability is due to a lack of proper input sanitization while querying the external authentication server. An attacker could exploit this vulnerability by sending a crafted query through an external authentication web page. A successful exploit could allow the attacker to gain access to sensitive information, including user credentials from the external authentication server. To exploit this vulnerability, an attacker would need valid operator-level (or higher) credentials.
解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
应用 cisco email_security_appliance * Up to
(excluding)
14.0.2-020
运行在以下环境
应用 cisco secure_email_and_web_manager * Up to
(excluding)
13.6.2-090
运行在以下环境
应用 cisco secure_email_and_web_manager * From
(including)
14.1
Up to
(excluding)
14.1.0-227
CVSS3评分
7.7
  • 攻击路径
    网络
  • 攻击复杂度
  • 权限要求
  • 影响范围
    已更改
  • 用户交互
  • 可用性
  • 保密性
  • 完整性
CWE-ID 漏洞类型
CWE-200 信息暴露
阿里云安全产品覆盖情况