CVE-2021-1561
Cisco Secure Email and Web Manager Spam Quarantine Unauthorized Access Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the spam quarantine feature of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), could allow an authenticated, remote attacker to gain unauthorized access and modify the spam quarantine settings of another user. This vulnerability exists because access to the spam quarantine feature is not properly restricted. An attacker could exploit this vulnerability by sending malicious requests to an affected system. A successful exploit could allow the attacker to modify another user's spam quarantine settings, possibly disabling security controls or viewing email messages stored on the spam quarantine interfaces.
Una vulnerabilidad en la funcionalidad spam quarantine de Cisco Secure Email and Web Manager, anteriormente Cisco Security Management Appliance (SMA), podría permitir a un atacante autenticado remoto conseguir acceso no autorizado y modificar la configuración de spam quarantine de otro usuario. Esta vulnerabilidad se presenta porque el acceso a la función de cuarentena de spam no está debidamente restringido. Un atacante podría explotar esta vulnerabilidad mediante el envío de peticiones maliciosas a un sistema afectado. Una explotación con éxito podría permitir al atacante modificar la configuración de spam quarantine de otro usuario, posiblemente deshabilitando los controles de seguridad o visualizando los mensajes de correo electrónico almacenados en las interfaces de spam quarantine.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2020-11-13 CVE Reserved
- 2021-08-18 CVE Published
- 2023-03-11 EPSS Updated
- 2024-11-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
- CWE-302: Authentication Bypass by Assumed-Immutable Data
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-spam-jPxUXMk | 2023-11-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Secure Email And Web Manager Search vendor "Cisco" for product "Secure Email And Web Manager" | <= 14.1 Search vendor "Cisco" for product "Secure Email And Web Manager" and version " <= 14.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Secure Email And Web Manager Search vendor "Cisco" for product "Secure Email And Web Manager" | - | - |
Safe
|