Vulnerability Description
A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to obtain sensitive network information.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Asyncos | 11.0.0-128 |
| Cisco | Secure Email And Web Manager M170 | - |
| Cisco | Secure Email And Web Manager M190 | - |
| Cisco | Secure Email And Web Manager M195 | - |
| Cisco | Secure Email And Web Manager M380 | - |
| Cisco | Secure Email And Web Manager M390 | - |
| Cisco | Secure Email And Web Manager M390X | - |
| Cisco | Secure Email And Web Manager M395 | - |
| Cisco | Secure Email And Web Manager M680 | - |
| Cisco | Secure Email And Web Manager M690 | - |
| Cisco | Secure Email And Web Manager M690X | - |
| Cisco | Secure Email And Web Manager M695 | - |
Related Weaknesses (CWE)
References
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvr92383Vendor Advisory
FAQ
What is CVE-2020-3122?
CVE-2020-3122 is a vulnerability with a CVSS score of 5.3 (MEDIUM). A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to obtain sensitive network...
How severe is CVE-2020-3122?
CVE-2020-3122 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-3122?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Asyncos, Cisco Secure Email And Web Manager M170, Cisco Secure Email And Web Manager M190, Cisco Secure Email And Web Manager M195, Cisco Secure Email And Web Manager M380.