#VU46247 Information disclosure in Cisco AsyncOS for Cisco Email Security Appliance - CVE-2020-3546
Published: September 3, 2020
Cisco AsyncOS for Cisco Email Security Appliance
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to insufficient validation of requests that are sent to the web-based management interface. A remote attacker can send a specially crafted request and obtain the IP addresses that are configured on the internal interfaces of the affected device.