Vulnerability Details CVE-2015-0624
The web framework in Cisco AsyncOS on Email Security Appliance (ESA), Content Security Management Appliance (SMA), and Web Security Appliance (WSA) devices allows remote attackers to trigger redirects via a crafted HTTP header, aka Bug IDs CSCur44412, CSCur44415, CSCur89630, CSCur89636, CSCur89633, and CSCur89639.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 36.5%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2015-0624
-
cpe:2.3:h:cisco:content_security_management_appliance:-
-
cpe:2.3:h:cisco:web_security_appliance:-
-
cpe:2.3:o:cisco:email_security_appliance_firmware:-