HTTP Response Splitting Vulnerability in Cisco Email Security Appliances
CVE-2022-20772
4.7MEDIUM
Summary
A vulnerability exists in Cisco Email Security Appliance and Cisco Secure Email and Web Manager that could allow an unauthenticated remote attacker to conduct an HTTP response splitting attack. This issue arises from the application’s failure to properly sanitize input values, making it possible for an attacker to inject malicious HTTP headers. By doing so, they can manipulate the response body or partition the response into multiple parts, leading to potential security breaches.
Affected Version(s)
Cisco Secure Email 13.5.1-277
Cisco Secure Email 14.0.0-698
Cisco Secure Email 14.2.0-620
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
- đź‘ľ
Exploit known to exist
Vulnerability published
Vulnerability Reserved