This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Cisco First view 2022-11-04
Product Secure Email And Web Manager Firmware Last view 2022-11-04
Version Type Os
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:o:cisco:secure_email_and_web_manager_firmware:*:*:*:*:*:*:*:* 1

Related : CVE

  Date Alert Description
5.3 2022-11-04 CVE-2022-20772

A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack.

This vulnerability is due to the failure of the application or its environment to properly sanitize input values. An attacker could exploit this vulnerability by injecting malicious HTTP headers, controlling the response body, or splitting the response into multiple responses.

CWE : Common Weakness Enumeration

%idName
100% (1) CWE-74 Failure to Sanitize Data into a Different Plane ('Injection')