NA

CVE-2022-20772

Published: 04/11/2022 Updated: 25/01/2024
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenticated, remote malicious user to conduct an HTTP response splitting attack. This vulnerability is due to the failure of the application or its environment to properly sanitize input values. An attacker could exploit this vulnerability by injecting malicious HTTP headers, controlling the response body, or splitting the response into multiple responses.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco email_security_appliance_firmware

cisco secure_email_and_web_manager_firmware

Vendor Advisories

A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack This vulnerability is due to the failure of the application or its environment to properly sanitize input values An attacker could exploit this vulnerability by ...