6.1
CVSSv3

CVE-2016-1423

Published: 28/10/2016 Updated: 29/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A vulnerability in the display of email messages in the Messages in Quarantine (MIQ) view in Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote malicious user to cause a user to click a malicious link in the MIQ view. The malicious link could be used to facilitate a cross-site scripting (XSS) or HTML injection attack. More Information: CSCuz02235. Known Affected Releases: 8.0.2-069. Known Fixed Releases: 9.1.1-038 9.7.2-047.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco email security appliance 9.1.0-032

cisco email security appliance 8.9.2-032

cisco email security appliance 9.0.5-000

cisco email security appliance 9.0.0-212

cisco email security appliance 9.1.0-101

cisco email security appliance 9.0.0

cisco email security appliance 8.9.0

cisco email security appliance 8.9.1-000

cisco email security appliance 9.0.0-461

cisco email security appliance 9.1.0

cisco email security appliance 9.1.0-011