SB2023011898 - URL filtering bypass in Cisco Email Security Appliance
Published: January 18, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security features bypass (CVE-ID: CVE-2023-20057)
The vulnerability allows a remote attacker to bypass URL filtering.
The vulnerability exists due to improper processing of URLs. A remote attacker can bypass the URL reputation filters that are configured for an affected device, which could allow malicious URLs to pass through the device.
Remediation
Install update from vendor's website.