XSS and HTML Injection Vulnerability in Cisco Email Security Appliance
CVE-2016-1423

6.1MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
28 October 2016

Summary

A vulnerability exists in the display of email messages within the Messages in Quarantine (MIQ) view in Cisco AsyncOS for Cisco Email Security Appliance (ESA). This flaw could potentially allow an unauthenticated remote attacker to craft a malicious link that, when clicked by a user, may lead to cross-site scripting (XSS) or HTML injection attacks. The affected version 8.0.2-069 has been identified, while fixed releases include 9.1.1-038 and 9.7.2-047, ensuring enhanced security measures against such threats.

Affected Version(s)

Cisco AsyncOS 8.0.2-069 Cisco AsyncOS 8.0.2-069

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.