Critical Flaw in Cisco Secure Email Gateway Exploited by Attackers
Cisco has disclosed a critical vulnerability in its Secure Email Gateway appliances, allowing attackers to run arbitrary commands as root on the devices. The flaw, rated CVSS 3.1 base score of 9.8 out of 10.0, was discovered when Cisco's product security incident response team became aware of active exploitation in September.
The vulnerability allows attackers to inject malicious SQL statements in an email and have the gateway execute them, without requiring a login or access to the management interface. The company has already upgraded affected cloud devices to AsyncOS 16.5.0-780 and is urging customers to upgrade on-premises appliances to fixed versions.
Cisco also disclosed four more vulnerability classes rated 9.8 and one 7.5, affecting both Secure Email Gateway and Secure Email and Web Manager. The company noted that it was not aware of malicious use of these flaws apart from the exploited SQL injection flaw.