CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2021-1566

HIGH
7.4
CVSS Severity Score
EPSS Score0.1370%
EPSS Percentile29.61th
Published2021年6月16日
Last Modified2024年11月21日

Vulnerability Description

A vulnerability in the Cisco Advanced Malware Protection (AMP) for Endpoints integration of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to intercept traffic between an affected device and the AMP servers. This vulnerability is due to improper certificate validation when an affected device establishes TLS connections. A man-in-the-middle attacker could exploit this vulnerability by sending a crafted TLS packet to an affected device. A successful exploit could allow the attacker to spoof a trusted host and then extract sensitive information or alter certain API requests.

Affected Platforms (CPE)

📦
Cisco

Email Security Appliance

All versions
💻
Cisco

Asyncos

< 12.5.3-035
💻
Cisco

Asyncos

>= 13.0 and < 13.0.0-030
💻
Cisco

Asyncos

>= 13.5 and < 13.5.3-010
📦
Cisco

Web Security Appliance

All versions
💻
Cisco

Asyncos

< 11.8.3-021
💻
Cisco

Asyncos

>= 12.0.0 and < 12.0.3-005
💻
Cisco

Asyncos

>= 12.5.0 and < 12.5.1-043

References & Advisories

相關漏洞威脅