CVE-2024-20258

A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface.

 This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
ciscoCNA
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 30%
VendorProductVersion
ciscosecure_email_gateway
11.0.3-238
ciscosecure_email_gateway
11.1.0-069
ciscosecure_email_gateway
11.1.0-128
ciscosecure_email_gateway
11.1.0-131
ciscosecure_email_gateway
12.0.0-419
ciscosecure_email_gateway
12.1.0-071
ciscosecure_email_gateway
12.1.0-087
ciscosecure_email_gateway
12.1.0-089
ciscosecure_email_gateway
12.5.0-066
ciscosecure_email_gateway
12.5.3-041
ciscosecure_email_gateway
12.5.4-041
ciscosecure_email_gateway
13.0.0-392
ciscosecure_email_gateway
13.0.5-007
ciscosecure_email_gateway
13.5.1-277
ciscosecure_email_gateway
13.5.4-038
ciscosecure_email_gateway
14.0.0-698
ciscosecure_email_gateway
14.2.0-620
ciscosecure_email_gateway
14.2.1-020
ciscosecure_email_gateway
14.3.0-032
ciscosecure_email_gateway
15.0.0-104
ciscosecure_email_gateway
15.0.1-030
ciscosecure_email_gateway
15.5.0-048
ciscosecure_email_and_web_manager
9.0.0-087
ciscosecure_email_and_web_manager
11.0.0-115
ciscosecure_email_and_web_manager
11.0.1-161
ciscosecure_email_and_web_manager
11.5.1-105
ciscosecure_email_and_web_manager
12.0.0-452
ciscosecure_email_and_web_manager
12.0.1-011
ciscosecure_email_and_web_manager
12.5.0-636
ciscosecure_email_and_web_manager
12.5.0-658
ciscosecure_email_and_web_manager
12.5.0-670
ciscosecure_email_and_web_manager
12.5.0-678
ciscosecure_email_and_web_manager
12.8.1-002
ciscosecure_email_and_web_manager
12.8.1-021
ciscosecure_email_and_web_manager
13.0.0-277
ciscosecure_email_and_web_manager
13.6.2-078
ciscosecure_email_and_web_manager
13.8.1-068
ciscosecure_email_and_web_manager
13.8.1-074
ciscosecure_email_and_web_manager
13.8.1-108
ciscosecure_email_and_web_manager
14.0.0-404
ciscosecure_email_and_web_manager
14.1.0-223
ciscosecure_email_and_web_manager
14.1.0-227
ciscosecure_email_and_web_manager
14.2.0-212
ciscosecure_email_and_web_manager
14.2.0-224
ciscosecure_email_and_web_manager
14.2.1-020
ciscosecure_email_and_web_manager
14.3.0-120
ciscosecure_email_and_web_manager
15.0.0-334
𝑥
= Vulnerable software versions