← Back

CVE-2022-20664

nvd nist
Published: Jun 15, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.7
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Exploitability: 3.1 / Impact: 4.0
Source: NVD

Description

A vulnerability in the web management interface of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an authenticated, remote attacker to retrieve sensitive information from a Lightweight Directory Access Protocol (LDAP) external authentication server connected to an affected device. This vulnerability is due to a lack of proper input sanitization while querying the external authentication server. An attacker could exploit this vulnerability by sending a crafted query through an external authentication web page. A successful exploit could allow the attacker to gain access to sensitive information, including user credentials from the external authentication server. To exploit this vulnerability, an attacker would need valid operator-level (or higher) credentials.

Affected (3)

2 products
Email Security Appliance
Secure Email And Web Manager
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Before 14.0.2-020
Cisco
Before 13.6.2-090
From 14.1 to 14.1.0-227

Timeline

No history available yet.