Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2015-0577


Vulnerability Score 4.3 4.3
CVE Id CVE-2015-0577
Last Modified 17 Sep 2015 12:32:35
Published 14 Jan 2015 02:59:01
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE



Multiple cross-site scripting (XSS) vulnerabilities in the IronPort Spam Quarantine (ISQ) page in Cisco AsyncOS, as used on the Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA), allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCus22925 and CSCup08113.

Vulnerable Systems

Operating System

  • Cisco Asyncos -


CISCO - 20150113 Cisco AsyncOS ISQ XSS Vulnerability

SECTRACK - 1031544

BID - 72056

SECUNIA - 62289

XF - cisco-asyncos-cve20150577-xss(100556)

Last Updated: 27 May 2016 11:07:36