Vulnslist

find the latest Cisco vulnerabilities

CVE-2020-3447

A vulnerability in the CLI of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to excessive verbosity in certain log subscriptions. An attacker could exploit this vulnerability by accessing specific log files on an affected device. A successful exploit could allow the attacker to obtain sensitive log data, which may include user credentials. To exploit this vulnerability, the attacker would need to have valid credentials at the operator level or higher on the affected device.

SeverityMEDIUM
CVSS5.5
CWECWE-532
KEV
Published
Modified

Related Products

Product Advisory
Cisco Nexus Dashboard cisco-sa-esa-sma-log-YxQ6g2kG
Cisco Application Centric Infrastructure Virtual Edge cisco-sa-esa-sma-log-YxQ6g2kG
Cisco Secure Email and Web Manager cisco-sa-esa-sma-log-YxQ6g2kG
Cisco Secure Email cisco-sa-esa-sma-log-YxQ6g2kG
Cisco Email Security Appliance (ESA) cisco-sa-esa-sma-log-YxQ6g2kG
Cisco Content Security Management Appliance (SMA) cisco-sa-esa-sma-log-YxQ6g2kG