3.5
CVSSv2

CVE-2019-12635

Published: 05/09/2019 Updated: 08/10/2020
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N

Vulnerability Summary

A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software could allow an authenticated, remote malicious user to gain out-of-scope access to email. The vulnerability exists because the affected software does not correctly implement role permission controls. An attacker could exploit this vulnerability by using a custom role with specific permissions. A successful exploit could allow the malicious user to access the spam quarantine of other users.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco content security management appliance

Vendor Advisories

A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software and Cisco Email Security Appliance (ESA) could allow an authenticated, remote attacker to gain out-of-scope access to email The vulnerability exists because the affected software does not correctly implement role permission controls An attack ...