PT-2018-8640 · Cisco · Cisco Email Security Appliance+1

CVE-2018-0140

·

Publicado

2018-02-08

·

Atualizado

2023-02-21

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Cisco Email Security Appliance (affected versions not specified) Cisco Content Security Management Appliance (affected versions not specified)
Description: A issue in the spam quarantine could allow an authenticated, remote attacker to download any message from the spam quarantine by modifying browser string information. This is due to a lack of verification of authenticated user accounts. An attacker could exploit this by modifying browser strings to see messages submitted by other users to the spam quarantine within their company.
Recommendations: For Cisco Email Security Appliance, update to a version that includes the fix for the issue. For Cisco Content Security Management Appliance, update to a version that includes the fix for the issue. As a temporary workaround, consider restricting access to the spam quarantine feature until a patch is available.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-0140

Produtos afetados

Cisco Content Security Management Appliance
Cisco Email Security Appliance