CyberSec.Space Logo
Back to CVE Browser

CVE-2021-1566

HIGH
7.4
CVSS Severity Score
EPSS Score0.1370%
EPSS Percentile29.61th
PublishedJun 16, 2021
Last ModifiedNov 21, 2024

Vulnerability Description

A vulnerability in the Cisco Advanced Malware Protection (AMP) for Endpoints integration of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to intercept traffic between an affected device and the AMP servers. This vulnerability is due to improper certificate validation when an affected device establishes TLS connections. A man-in-the-middle attacker could exploit this vulnerability by sending a crafted TLS packet to an affected device. A successful exploit could allow the attacker to spoof a trusted host and then extract sensitive information or alter certain API requests.

Affected Platforms (CPE)

πŸ“¦
Cisco

Email Security Appliance

All versions
πŸ’»
Cisco

Asyncos

< 12.5.3-035
πŸ’»
Cisco

Asyncos

>= 13.0 and < 13.0.0-030
πŸ’»
Cisco

Asyncos

>= 13.5 and < 13.5.3-010
πŸ“¦
Cisco

Web Security Appliance

All versions
πŸ’»
Cisco

Asyncos

< 11.8.3-021
πŸ’»
Cisco

Asyncos

>= 12.0.0 and < 12.0.3-005
πŸ’»
Cisco

Asyncos

>= 12.5.0 and < 12.5.1-043

References & Advisories

Related Vulnerabilities