Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9p6x-p535-c54c

Опубликовано: 04 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to the failure of the application or its environment to properly sanitize input values. An attacker could exploit this vulnerability by injecting malicious HTTP headers, controlling the response body, or splitting the response into multiple responses.

A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to the failure of the application or its environment to properly sanitize input values. An attacker could exploit this vulnerability by injecting malicious HTTP headers, controlling the response body, or splitting the response into multiple responses.

EPSS

Процентиль: 60%
0.00401
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-113
CWE-74

Связанные уязвимости

CVSS3: 4.7
nvd
больше 3 лет назад

A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to the failure of the application or its environment to properly sanitize input values. An attacker could exploit this vulnerability by injecting malicious HTTP headers, controlling the response body, or splitting the response into multiple responses.

CVSS3: 5.3
fstec
больше 3 лет назад

Уязвимость системы обеспечения безопасности электронной почты Cisco Email Security Appliance (ESA) и устройства управления защитой контента Cisco Secure Email and Web Manager, связанная с непринятием мер по обработке последовательностей CRLF в HTTP-заголовках, позволяющая нарушителю выполнять атаки с разделением ответов HTTP

EPSS

Процентиль: 60%
0.00401
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-113
CWE-74