Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h6wq-6w3g-434q

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software could allow an authenticated, remote attacker to gain out-of-scope access to email. The vulnerability exists because the affected software does not correctly implement role permission controls. An attacker could exploit this vulnerability by using a custom role with specific permissions. A successful exploit could allow the attacker to access the spam quarantine of other users.

A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software could allow an authenticated, remote attacker to gain out-of-scope access to email. The vulnerability exists because the affected software does not correctly implement role permission controls. An attacker could exploit this vulnerability by using a custom role with specific permissions. A successful exploit could allow the attacker to access the spam quarantine of other users.

EPSS

Процентиль: 27%
0.00095
Низкий

Связанные уязвимости

CVSS3: 4.3
nvd
больше 6 лет назад

A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software could allow an authenticated, remote attacker to gain out-of-scope access to email. The vulnerability exists because the affected software does not correctly implement role permission controls. An attacker could exploit this vulnerability by using a custom role with specific permissions. A successful exploit could allow the attacker to access the spam quarantine of other users.

CVSS3: 4.3
fstec
больше 6 лет назад

Уязвимость модуля авторизации программного обеспечения системы управления защитой контента Cisco Content Security Management Appliance, позволяющая нарушителю получить доступ к сообщениям категории спам других пользователей

EPSS

Процентиль: 27%
0.00095
Низкий