CVE-2015-0624
The web framework in Cisco AsyncOS on Email Security Appliance (ESA), Content Security Management Appliance (SMA), and Web Security Appliance (WSA) devices allows remote attackers to trigger redirects via a crafted HTTP header, aka Bug IDs CSCur44412,…
Does this matter?
Lower severity and a low EPSS score (2.16%). Track it; it rarely justifies an emergency change on its own.
Description
The web framework in Cisco AsyncOS on Email Security Appliance (ESA), Content Security Management Appliance (SMA), and Web Security Appliance (WSA) devices allows remote attackers to trigger redirects via a crafted HTTP header, aka Bug IDs CSCur44412, CSCur44415, CSCur89630, CSCur89636, CSCur89633, and CSCur89639.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.16% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- cisco/content security management appliance · cisco/web security appliance · cisco/email security appliance firmware
- Source
- psirt@cisco.com
References
- http://packetstormsecurity.com/files/130525/Cisco-Ironport-AsyncOS-HTTP-Header-Injection.htmlExploit
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0624Vendor Advisory
- http://www.securityfocus.com/bid/72702
- http://www.securitytracker.com/id/1031781
- http://www.securitytracker.com/id/1031782
- http://packetstormsecurity.com/files/130525/Cisco-Ironport-AsyncOS-HTTP-Header-Injection.htmlExploit
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0624Vendor Advisory
- http://www.securityfocus.com/bid/72702
- http://www.securitytracker.com/id/1031781
- http://www.securitytracker.com/id/1031782
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.