Incorrect authorization in Cisco AsyncOS for Secure Web Appliance and Cisco AsyncOS for Cisco Email Security Appliance - CVE-2022-20942
Published: November 4, 2022
Vulnerability details
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to weak enforcement of back-end authorization checks within the web-based management interface. A remote authenticated user can send a specially crafted HTTP request to the affected device and obtain confidential data that is stored on the affected device.
Affected software
Cisco AsyncOS for Cisco Email Security Appliance
How to mitigate CVE-2022-20942
Cisco AsyncOS for Cisco Email Security Appliance - addressed in versions 14.2.1-015, 14.3.0-023