Incorrect authorization in Cisco AsyncOS for Cisco Email Security Appliance and Cisco AsyncOS for Web Security Appliances - CVE-2022-20942
Published: November 4, 2022
Cisco AsyncOS for Cisco Email Security Appliance
Cisco AsyncOS for Web Security Appliances
Cisco Systems, Inc
Description
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to weak enforcement of back-end authorization checks within the web-based management interface. A remote authenticated user can send a specially crafted HTTP request to the affected device and obtain confidential data that is stored on the affected device.