HTTP Response Splitting Vulnerability in Cisco Email Security Appliances
CVE-2022-20772

4.7MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
4 November 2022

Badges

đź‘ľ Exploit Exists

Summary

A vulnerability exists in Cisco Email Security Appliance and Cisco Secure Email and Web Manager that could allow an unauthenticated remote attacker to conduct an HTTP response splitting attack. This issue arises from the application’s failure to properly sanitize input values, making it possible for an attacker to inject malicious HTTP headers. By doing so, they can manipulate the response body or partition the response into multiple parts, leading to potential security breaches.

Affected Version(s)

Cisco Secure Email 13.5.1-277

Cisco Secure Email 14.0.0-698

Cisco Secure Email 14.2.0-620

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • đź‘ľ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.