// For flags

CVE-2021-1561

Cisco Secure Email and Web Manager Spam Quarantine Unauthorized Access Vulnerability

Severity Score

5.4
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability in the spam quarantine feature of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), could allow an authenticated, remote attacker to gain unauthorized access and modify the spam quarantine settings of another user. This vulnerability exists because access to the spam quarantine feature is not properly restricted. An attacker could exploit this vulnerability by sending malicious requests to an affected system. A successful exploit could allow the attacker to modify another user's spam quarantine settings, possibly disabling security controls or viewing email messages stored on the spam quarantine interfaces.

Una vulnerabilidad en la funcionalidad spam quarantine de Cisco Secure Email and Web Manager, anteriormente Cisco Security Management Appliance (SMA), podría permitir a un atacante autenticado remoto conseguir acceso no autorizado y modificar la configuración de spam quarantine de otro usuario. Esta vulnerabilidad se presenta porque el acceso a la función de cuarentena de spam no está debidamente restringido. Un atacante podría explotar esta vulnerabilidad mediante el envío de peticiones maliciosas a un sistema afectado. Una explotación con éxito podría permitir al atacante modificar la configuración de spam quarantine de otro usuario, posiblemente deshabilitando los controles de seguridad o visualizando los mensajes de correo electrónico almacenados en las interfaces de spam quarantine.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-11-13 CVE Reserved
  • 2021-08-18 CVE Published
  • 2023-03-11 EPSS Updated
  • 2024-09-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-287: Improper Authentication
  • CWE-302: Authentication Bypass by Assumed-Immutable Data
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Secure Email And Web Manager
Search vendor "Cisco" for product "Secure Email And Web Manager"
<= 14.1
Search vendor "Cisco" for product "Secure Email And Web Manager" and version " <= 14.1"
-
Affected
in Cisco
Search vendor "Cisco"
Secure Email And Web Manager
Search vendor "Cisco" for product "Secure Email And Web Manager"
--
Safe