HTTP Response Splitting Vulnerability in Cisco Email Security Appliances
CVE-2022-20772
4.7MEDIUM
What is CVE-2022-20772?
A vulnerability exists in Cisco Email Security Appliance and Cisco Secure Email and Web Manager that could allow an unauthenticated remote attacker to conduct an HTTP response splitting attack. This issue arises from the application’s failure to properly sanitize input values, making it possible for an attacker to inject malicious HTTP headers. By doing so, they can manipulate the response body or partition the response into multiple parts, leading to potential security breaches.
Affected Version(s)
Cisco Secure Email 13.5.1-277
Cisco Secure Email 14.0.0-698
Cisco Secure Email 14.2.0-620