CVE-2018-0140 Details
Description
A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance could allow an authenticated, remote attacker to download any message from the spam quarantine by modifying browser string information. The vulnerability is due to a lack of verification of authenticated user accounts. An attacker could exploit this vulnerability by modifying browser strings to see messages submitted by other users to the spam quarantine within their company. Cisco Bug IDs: CSCvg39759, CSCvg42295.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 2, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180207-esacsm | CVE | Vendor Advisory |
| http://www.securityfocus.com/bid/103090 | CVE | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040338 | CVE | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040339 | CVE | Third Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180207-esacsm | [email protected] | Vendor Advisory |
| http://www.securityfocus.com/bid/103090 | [email protected] | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040338 | [email protected] | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040339 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-425 | Direct Request ('Forced Browsing') | [email protected] |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco email security appliance firmware | 9.8.0-112 10.0.1-087 11.0.0-274 |
CPE
Remediation
| |
| cisco email security appliance c160 | All versions |
CPE
Remediation
| |
| cisco email security appliance c170 | All versions |
CPE
Remediation
| |
| cisco email security appliance c190 | All versions |
CPE
Remediation
| |
| cisco email security appliance c370 | All versions |
CPE
Remediation
| |
| cisco email security appliance c370d | All versions |
CPE
Remediation
| |
| cisco email security appliance c380 | All versions |
CPE
Remediation
| |
| cisco email security appliance c390 | All versions |
CPE
Remediation
| |
| cisco email security appliance c670 | All versions |
CPE
Remediation
| |
| cisco email security appliance c680 | All versions |
CPE
Remediation
| |
| cisco email security appliance c690 | All versions |
CPE
Remediation
| |
| cisco email security appliance c690x | All versions |
CPE
Remediation
| |
| cisco email security appliance x1070 | All versions |
CPE
Remediation
| |
| cisco content security management appliance | 10.0.0-096 10.1.0-037 10.1.0-052 11.0.0-115 |
CPE
Remediation
| |
| cisco content security management appliance sma m190 | All versions |
CPE
Remediation
| |
| cisco content security management appliance sma m390 | All versions |
CPE
Remediation
| |
| cisco content security management appliance sma m390x | All versions |
CPE
Remediation
| |
| cisco content security management appliance sma m690 | All versions |
CPE
Remediation
| |
| cisco content security management appliance sma m690x | All versions |
CPE
Remediation
| |
Change History
12 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Feb 21, 2023 | CPE Deprecation Remap | [email protected] |
| Feb 21, 2023 | CPE Deprecation Remap | [email protected] |
| Feb 21, 2023 | CPE Deprecation Remap | [email protected] |
| Sep 4, 2020 | Modified Analysis | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Mar 13, 2018 | Initial Analysis | [email protected] |
| Feb 23, 2018 | CVE Modified | [email protected] |
| Feb 9, 2018 | CVE Modified | [email protected] |