CVE Database
/

CVE-2022-20772

Back to search

CVE-2022-20772

Published: Nov 3, 2022

Modified: Oct 25, 2024

PUBLISHED

CVSS v3.1

4.7

MEDIUM

Description

A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to the failure of the application or its environment to properly sanitize input values. An attacker could exploit this vulnerability by injecting malicious HTTP headers, controlling the response body, or splitting the response into multiple responses.

VendorProductVersions

Cisco

Cisco Secure Email

affected
13.5.1-277
affected
14.0.0-698
affected
14.2.0-620

Cisco

Cisco Secure Email and Web Manager

affected
14.0.0-404
affected
14.1.0-223
affected
14.1.0-227
affected
14.2.0-212

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Changed

Confidentiality

None

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now