CVE-2023-20057
 
Severity Score
5.3
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device.
This vulnerability is due to improper processing of URLs. An attacker could exploit this vulnerability by crafting a URL in a particular way. A successful exploit could allow the attacker to bypass the URL reputation filters that are configured for an affected device, which could allow malicious URLs to pass through the device.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-10-27 CVE Reserved
- 2023-01-19 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-11 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
- CWE-792: Incomplete Filtering of One or More Instances of Special Elements
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Asyncos Search vendor "Cisco" for product "Asyncos" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Email Security Appliance C160 Search vendor "Cisco" for product "Email Security Appliance C160" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Asyncos Search vendor "Cisco" for product "Asyncos" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Email Security Appliance C170 Search vendor "Cisco" for product "Email Security Appliance C170" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Asyncos Search vendor "Cisco" for product "Asyncos" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Email Security Appliance C190 Search vendor "Cisco" for product "Email Security Appliance C190" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Asyncos Search vendor "Cisco" for product "Asyncos" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Email Security Appliance C370 Search vendor "Cisco" for product "Email Security Appliance C370" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Asyncos Search vendor "Cisco" for product "Asyncos" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Email Security Appliance C370d Search vendor "Cisco" for product "Email Security Appliance C370d" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Asyncos Search vendor "Cisco" for product "Asyncos" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Email Security Appliance C380 Search vendor "Cisco" for product "Email Security Appliance C380" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Asyncos Search vendor "Cisco" for product "Asyncos" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Email Security Appliance C390 Search vendor "Cisco" for product "Email Security Appliance C390" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Asyncos Search vendor "Cisco" for product "Asyncos" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Email Security Appliance C670 Search vendor "Cisco" for product "Email Security Appliance C670" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Asyncos Search vendor "Cisco" for product "Asyncos" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Email Security Appliance C680 Search vendor "Cisco" for product "Email Security Appliance C680" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Asyncos Search vendor "Cisco" for product "Asyncos" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Email Security Appliance C690 Search vendor "Cisco" for product "Email Security Appliance C690" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Asyncos Search vendor "Cisco" for product "Asyncos" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Email Security Appliance C690x Search vendor "Cisco" for product "Email Security Appliance C690x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Asyncos Search vendor "Cisco" for product "Asyncos" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Email Security Appliance X1070 Search vendor "Cisco" for product "Email Security Appliance X1070" | - | - |
Safe
|