CVE-2015-0577
Last modified
CVE-2015-0577 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in the IronPort Spam Quarantine (ISQ) page in Cisco AsyncOS, as used on the Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA), allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCus22925 and CSCup08113.. EPSS estimates a 1.16% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the IronPort Spam Quarantine (ISQ) page in Cisco AsyncOS, as used on the Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA), allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCus22925 and CSCup08113.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Asyncos | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-0577?
How severe is CVE-2015-0577?
How do I fix CVE-2015-0577?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-0571The WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x…7.8
- CVE-2015-0572Multiple race conditions in drivers/char/adsprpc.c and drive…7
- CVE-2015-0573drivers/media/platform/msm/broadcast/tsc.c in the TSC driver…9.8
- CVE-2015-0574In all Qualcomm products with Android releases from CAF usin…
- CVE-2015-0575In all Qualcomm products with Android releases from CAF usin…
- CVE-2015-0576In all Qualcomm products with Android releases from CAF usin…
- CVE-2015-0578Cisco Adaptive Security Appliance (ASA) Software, when a DHC…
- CVE-2015-0579Cisco TelePresence Video Communication Server (VCS) and Cisc…
- CVE-2015-0580Multiple SQL injection vulnerabilities in the ACS View repor…
- CVE-2015-0581The XML parser in Cisco Prime Service Catalog before 10.1 al…
- CVE-2015-0582The High Availability (HA) subsystem in Cisco NX-OS on MDS 9…
- CVE-2015-0583Cisco WebEx Meeting Center does not properly restrict the co…
Are you affected by CVE-2015-0577?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
