URL Filtering Bypass in Cisco Email Security Appliance Software
CVE-2023-20057
5.3MEDIUM
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 20 January 2023
What is CVE-2023-20057?
A vulnerability exists in the URL filtering mechanism of the Cisco AsyncOS Software for the Email Security Appliance, allowing unauthenticated remote attackers to bypass security measures. This issue arises from improper processing of URLs, enabling an attacker to craft a malicious URL that evades URL reputation filters. If successful, the exploit permits harmful URLs to infiltrate the device’s security barriers, potentially leading to significant breaches in security protocols.
Affected Version(s)
Cisco Email Security Appliance (ESA) 10.0.1-087