← Back

CVE-2016-9202

nvd nist
Published: Dec 14, 2016Modified: May 6, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) Switches could allow an unauthenticated, remote attacker to conduct a persistent cross-site scripting (XSS) attack against a user of the affected interface on an affected device. More Information: CSCvb37346. Known Affected Releases: 9.1.1-036 9.7.1-066.

Affected (16)

1 product
Email Security Appliance
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 9.1.1-036
Version 9.1.2-023
Version 9.1.2-028
Version 9.1.2-036
Version 9.4.0
Version 9.4.4-000
Version 9.5.0-000
Version 9.5.0-201
Version 9.6.0-000
Version 9.6.0-042
Version 9.6.0-051
Version 9.7.0-125
Version 9.7.1-066
Version 9.7.2-046
Version 9.7.2-047
Version 9.7.2-054

References (6)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.