CVE-2020-3447
Cisco Email Security Appliance and Cisco Content Security Management Appliance Information Disclosure Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the CLI of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to excessive verbosity in certain log subscriptions. An attacker could exploit this vulnerability by accessing specific log files on an affected device. A successful exploit could allow the attacker to obtain sensitive log data, which may include user credentials. To exploit this vulnerability, the attacker would need to have valid credentials at the operator level or higher on the affected device.
Una vulnerabilidad en la CLI de Cisco AsyncOS para Cisco Email Security Appliance (ESA) y Cisco AsyncOS para Cisco Content Security Management Appliance (SMA) podría permitir a un atacante remoto autenticado acceder a información confidencial sobre un dispositivo afectado. La vulnerabilidad es debido a la excesiva verbosidad en determinadas suscripciones de registro. Un atacante podría explotar esta vulnerabilidad mediante el acceso a archivos de registro específicos sobre un dispositivo afectado. Una explotación con éxito podría permitir al atacante obtener datos de registro confidenciales, que pueden incluir credenciales de usuario. Para explotar esta vulnerabilidad, el atacante podría necesitar tener credenciales válidas a nivel de operador o superior en el dispositivo afectado.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2019-12-12 CVE Reserved
- 2020-08-17 CVE Published
- 2024-04-22 EPSS Updated
- 2024-11-13 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-532: Insertion of Sensitive Information into Log File
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Content Security Management Appliance Search vendor "Cisco" for product "Content Security Management Appliance" | < 13.6.1-201 Search vendor "Cisco" for product "Content Security Management Appliance" and version " < 13.6.1-201" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Email Security Appliance Search vendor "Cisco" for product "Email Security Appliance" | < 13.5.1 Search vendor "Cisco" for product "Email Security Appliance" and version " < 13.5.1" | - |
Affected
|