// For flags

CVE-2016-9202

 

Severity Score

6.1
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) Switches could allow an unauthenticated, remote attacker to conduct a persistent cross-site scripting (XSS) attack against a user of the affected interface on an affected device. More Information: CSCvb37346. Known Affected Releases: 9.1.1-036 9.7.1-066.

Una vulnerabilidad en la interfaz de administración basada en web de Cisco Email Security Appliance (ESA) Switches podría permitir a un atacante remoto no autenticado llevar a cabo un ataque de XSS sostenido contra el usuario de la interfaz afectada en un dispositivo afectado. Más Información: CSCvb37346. Lanzamientos Afectados Conocidos: 9.1.1-036 9.7.1-066.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2016-11-06 CVE Reserved
  • 2016-12-14 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Email Security Appliance
Search vendor "Cisco" for product "Email Security Appliance"
9.1.1-036
Search vendor "Cisco" for product "Email Security Appliance" and version "9.1.1-036"
-
Affected
Cisco
Search vendor "Cisco"
Email Security Appliance
Search vendor "Cisco" for product "Email Security Appliance"
9.1.2-023
Search vendor "Cisco" for product "Email Security Appliance" and version "9.1.2-023"
-
Affected
Cisco
Search vendor "Cisco"
Email Security Appliance
Search vendor "Cisco" for product "Email Security Appliance"
9.1.2-028
Search vendor "Cisco" for product "Email Security Appliance" and version "9.1.2-028"
-
Affected
Cisco
Search vendor "Cisco"
Email Security Appliance
Search vendor "Cisco" for product "Email Security Appliance"
9.1.2-036
Search vendor "Cisco" for product "Email Security Appliance" and version "9.1.2-036"
-
Affected
Cisco
Search vendor "Cisco"
Email Security Appliance
Search vendor "Cisco" for product "Email Security Appliance"
9.4.0
Search vendor "Cisco" for product "Email Security Appliance" and version "9.4.0"
-
Affected
Cisco
Search vendor "Cisco"
Email Security Appliance
Search vendor "Cisco" for product "Email Security Appliance"
9.4.4-000
Search vendor "Cisco" for product "Email Security Appliance" and version "9.4.4-000"
-
Affected
Cisco
Search vendor "Cisco"
Email Security Appliance
Search vendor "Cisco" for product "Email Security Appliance"
9.5.0-000
Search vendor "Cisco" for product "Email Security Appliance" and version "9.5.0-000"
-
Affected
Cisco
Search vendor "Cisco"
Email Security Appliance
Search vendor "Cisco" for product "Email Security Appliance"
9.5.0-201
Search vendor "Cisco" for product "Email Security Appliance" and version "9.5.0-201"
-
Affected
Cisco
Search vendor "Cisco"
Email Security Appliance
Search vendor "Cisco" for product "Email Security Appliance"
9.6.0-000
Search vendor "Cisco" for product "Email Security Appliance" and version "9.6.0-000"
-
Affected
Cisco
Search vendor "Cisco"
Email Security Appliance
Search vendor "Cisco" for product "Email Security Appliance"
9.6.0-042
Search vendor "Cisco" for product "Email Security Appliance" and version "9.6.0-042"
-
Affected
Cisco
Search vendor "Cisco"
Email Security Appliance
Search vendor "Cisco" for product "Email Security Appliance"
9.6.0-051
Search vendor "Cisco" for product "Email Security Appliance" and version "9.6.0-051"
-
Affected
Cisco
Search vendor "Cisco"
Email Security Appliance
Search vendor "Cisco" for product "Email Security Appliance"
9.7.0-125
Search vendor "Cisco" for product "Email Security Appliance" and version "9.7.0-125"
-
Affected
Cisco
Search vendor "Cisco"
Email Security Appliance
Search vendor "Cisco" for product "Email Security Appliance"
9.7.1-066
Search vendor "Cisco" for product "Email Security Appliance" and version "9.7.1-066"
-
Affected
Cisco
Search vendor "Cisco"
Email Security Appliance
Search vendor "Cisco" for product "Email Security Appliance"
9.7.2-046
Search vendor "Cisco" for product "Email Security Appliance" and version "9.7.2-046"
-
Affected
Cisco
Search vendor "Cisco"
Email Security Appliance
Search vendor "Cisco" for product "Email Security Appliance"
9.7.2-047
Search vendor "Cisco" for product "Email Security Appliance" and version "9.7.2-047"
-
Affected
Cisco
Search vendor "Cisco"
Email Security Appliance
Search vendor "Cisco" for product "Email Security Appliance"
9.7.2-054
Search vendor "Cisco" for product "Email Security Appliance" and version "9.7.2-054"
-
Affected