SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-0624

The web framework in Cisco AsyncOS on Email Security Appliance (ESA), Content Security Management Appliance (SMA), and Web Security Appliance (WSA) devices allows remote attackers to trigger redirects via a crafted HTTP header, aka Bug IDs CSCur44412,…

MEDIUM 4.3EPSS 2.16%

Does this matter?

Lower severity and a low EPSS score (2.16%). Track it; it rarely justifies an emergency change on its own.

Description

The web framework in Cisco AsyncOS on Email Security Appliance (ESA), Content Security Management Appliance (SMA), and Web Security Appliance (WSA) devices allows remote attackers to trigger redirects via a crafted HTTP header, aka Bug IDs CSCur44412, CSCur44415, CSCur89630, CSCur89636, CSCur89633, and CSCur89639.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
2.16% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
cisco/content security management appliance · cisco/web security appliance · cisco/email security appliance firmware
Source
psirt@cisco.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.