Home

Description

A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

PUBLISHED Reserved 2023-11-08 | Published 2024-11-06 | Updated 2024-11-06 | Assigner cisco




MEDIUM: 5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Problem types

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Product status

Default status
unknown

14.0.0-698
affected

14.2.0-620
affected

14.2.1-020
affected

14.3.0-032
affected

15.0.0-104
affected

15.0.1-030
affected

15.5.0-048
affected

15.5.1-055
affected

Default status
unknown

14.0.0-404
affected

14.1.0-223
affected

14.1.0-227
affected

14.2.0-212
affected

14.2.0-224
affected

14.2.1-020
affected

14.3.0-120
affected

15.0.0-334
affected

15.5.1-024
affected

15.5.1-029
affected

Default status
unknown

14.1.0-032
affected

14.1.0-047
affected

14.1.0-041
affected

14.0.2-012
affected

14.5.0-498
affected

14.0.3-014
affected

14.0.4-005
affected

14.5.1-008
affected

14.5.1-016
affected

15.0.0-355
affected

15.0.0-322
affected

15.1.0-287
affected

14.5.2-011
affected

15.2.0-116
affected

14.0.5-007
affected

15.2.0-164
affected

14.5.1-510
affected

14.5.1-607
affected

14.5.3-033
affected

References

sec.cloudapps.cisco.com/...cisco-sa-esa-wsa-sma-xss-zYm3f49n (cisco-sa-esa-wsa-sma-xss-zYm3f49n)

cve.org (CVE-2024-20504)

nvd.nist.gov (CVE-2024-20504)

Download JSON