CVE-2020-3447 is a medium-severity vulnerability affecting the CLI of Cisco AsyncOS for Email Security Appliance (ESA) and Content Security Management Appliance (SMA). It allows an authenticated, remote attacker to access sensitive information, potentially including user credentials, due to excessive verbosity in certain log subscriptions. Exploitation requires valid operator-level credentials or higher. There is no known active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 13.6.1-201CPE matchmatch criteria | cpe:2.3:a:cisco:content_security_management_appliance:*:*:*:*:*:*:*:* | ||
< 13.5.1CPE matchmatch criteria | cpe:2.3:a:cisco:email_security_appliance:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.