Home/Product/cisco content security management appliance
Product

cisco content security management appliance

27 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2021-1516
all versions
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Content Security Management Appliance (S
4.3MEDIUM
CVE-2021-1447
< 12.8.1-002
A vulnerability in the user account management system of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could
6.7MEDIUM
CVE-2021-1129
all versions
A vulnerability in the authentication for the general purpose APIs implementation of Cisco Email Security Appliance (ESA), Cisco C
5.3MEDIUM
CVE-2020-3117
< 13.0.0-187
A vulnerability in the API Framework of Cisco AsyncOS for Cisco Web Security Appliance (WSA) and Cisco Content Security Management
4.7MEDIUM
CVE-2019-1983
all versions
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisc
5.3MEDIUM
CVE-2020-3447
< 13.6.1-201
A vulnerability in the CLI of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco AsyncOS for Cisco Content Security
5.5MEDIUM
CVE-2020-3178
< 13.6.0
Multiple vulnerabilities in the web-based GUI of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) coul
6.1MEDIUM
CVE-2020-3164
< 13.6.0
A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appliance (ESA), Cisco Web Securit
5.3MEDIUM
CVE-2019-12635
< 12.5.0
A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software could allow an authentic
4.3MEDIUM
CVE-2018-15393
all versions
A vulnerability in the web-based management interface of Cisco Content Security Management Appliance (SMA) Software could allow an
4.8MEDIUM
CVE-2018-0140
all versions
A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance could all
6.5MEDIUM
CVE-2017-6783
all versions
A vulnerability in SNMP polling for the Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security M
4.3MEDIUM
CVE-2017-6661
all versions
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) and Cisco Content Security Managemen
6.1MEDIUM
CVE-2016-1411
all versions
A vulnerability in the update functionality of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA), Cisco Web Security
5.9MEDIUM
CVE-2016-6416
all versions
The FTP service in Cisco AsyncOS on Email Security Appliance (ESA) devices 9.6.0-000 through 9.9.6-026, Web Security Appliance (WS
5.9MEDIUM
CVE-2016-2183
all versions
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bou
7.5HIGH
CVE-2015-6321
all versions
Cisco AsyncOS before 8.5.7-042, 9.x before 9.1.0-032, 9.1.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-042 on Email Securi
CVE-2015-6288
all versions
Cisco Content Security Management Appliance (SMA) 7.8.0-000 does not properly validate credentials, which allows remote attackers
CVE-2015-4322
all versions
Cisco Content Security Management Appliance (SMA) 8.3.6-039, 9.1.0-31, and 9.1.0-103 improperly restricts the privileges available
CVE-2015-4288
all versions
The LDAP implementation on the Cisco Web Security Appliance (WSA) 8.5.0-000, Email Security Appliance (ESA) 8.5.7-042, and Content
CVE-2015-0624
all versions
The web framework in Cisco AsyncOS on Email Security Appliance (ESA), Content Security Management Appliance (SMA), and Web Securit
CVE-2014-3289
all versions
Cross-site scripting (XSS) vulnerability in the web management interface in Cisco AsyncOS on the Email Security Appliance (ESA) 8.
CVE-2014-2195
all versions
Cisco AsyncOS on Email Security Appliance (ESA) and Content Security Management Appliance (SMA) devices, when Active Directory is
CVE-2014-2119
all versions
The End User Safelist/Blocklist (aka SLBL) service in Cisco AsyncOS Software for Email Security Appliance (ESA) before 7.6.3-023 a
CVE-2013-5537
all versions
The web framework on Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance
CVE-2013-3395
all versions
Cross-site request forgery (CSRF) vulnerability in the web framework on Cisco IronPort Web Security Appliance (WSA) devices, Email
CVE-2013-3396
all versions
Cross-site scripting (XSS) vulnerability in the web framework in Cisco Content Security Management on Security Management Applianc
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin