Role Authorization Vulnerability in Cisco AsyncOS on Email Security and Content Management Appliances
CVE-2014-2195
Currently unrated
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 20 May 2014
What is CVE-2014-2195?
An authorization vulnerability exists in Cisco AsyncOS software running on Email Security Appliance (ESA) and Content Security Management Appliance (SMA) devices when Active Directory is enabled. This flaw arises from the improper handling of group names, which can be exploited by remote attackers to gain unauthorized role privileges through group-name similarity. This could lead to significant security risks, compromising the integrity of the affected systems.