← Back

CVE-2022-20772

nvd nist
Published: Nov 4, 2022Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to the failure of the application or its environment to properly sanitize input values. An attacker could exploit this vulnerability by injecting malicious HTTP headers, controlling the response body, or splitting the response into multiple responses.

Affected (5)

2 products
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
From 13.5.1 to 14.0.3-015
From 14.1 to 14.2.1-015
From 14.3 to 14.3.0-023
Running on/withPlatform Versions
Cisco
Email Security Appliance
All versions
Configuration B
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
From 14.2 to 14.2.0-217
From 14.3 to 14.3.0-115
Running on/withPlatform Versions
Cisco
Secure Email And Web Manager
All versions

Timeline

No history available yet.