Input validation error in Cisco Email Security Appliance and Cisco Secure Email and Web Manager - CVE-2023-20009
Published: February 15, 2023
Vulnerability identifier: #VU72309
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20009
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to insufficient validation of an uploaded Simple Network Management Protocol (SNMP) configuration file. A remote attacker can upload a specially crafted SNMP configuration file and execute arbitrary code as root.
Affected software
Cisco Email Security Appliance
Cisco Secure Email and Web Manager
Cisco Secure Email and Web Manager
How to mitigate CVE-2023-20009
Install updates from vendor's website.
Cisco Email Security Appliance - addressed in versions 12.5.4-041, 13.0.5-007, 13.5.4-038, 14.2.1-020, 14.3.0-032
Cisco Secure Email and Web Manager - addressed in versions 12.8.1-021, 13.8.1-108, 14.2.0-224, 14.2.1-020, 14.3.0-120
Cisco Secure Email and Web Manager - addressed in versions 12.8.1-021, 13.8.1-108, 14.2.0-224, 14.2.1-020, 14.3.0-120