4.3
CVSSv2

CVE-2014-2195

Published: 20/05/2014 Updated: 30/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Cisco AsyncOS on Email Security Appliance (ESA) and Content Security Management Appliance (SMA) devices, when Active Directory is enabled, does not properly handle group names, which allows remote malicious users to gain role privileges by leveraging group-name similarity, aka Bug ID CSCum86085.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco asyncos -

cisco content_security_management_appliance -

cisco email_security_appliance_firmware -