Improper Authentication in Cisco Systems, Inc products - CVE-2022-20798
Published: June 15, 2022
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error improper authentication checks when using the Lightweight Directory Access Protocol (LDAP) for external authentication. A remote non-authenticated attacker can bypass specially crafted data to the login page of the affected device, bypass the authenticated process and gain unauthorized access to the system.
Affected software
Cisco Secure Email and Web Manager
Cisco AsyncOS for Cisco Email Security Appliance
Cisco Email Security Appliance
How to mitigate CVE-2022-20798
Cisco AsyncOS for Cisco Email Security Appliance - update to 14.0.1-033
Cisco Email Security Appliance - update to 14.0.1-033