Impact
The vulnerability arises from improper control of a resource throughout its lifetime, a flaw categorized under CWE-664. The flaw can allow a malicious actor to misuse the resource, potentially leading to unauthorized actions or escalation of privileges, as reflected by the CVSS score of 9.8.
Affected Systems
Cisco Secure Email Gateway devices are affected. Specific advisory, so all installations of Cisco Secure Email Gateway should be considered potentially vulnerable until a patch is applied.
Risk and Exploitability
The high CVSS score indicates the vulnerability is severe; the EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the gateway’s administrative or management interfaces, given the nature of the flaw and the environment in which Cisco Secure Email operates. While no exploitation data is supplied, the potential for remote exploitation exists based on the severity rating.
OpenCVE Enrichment