Impact
The vulnerability, classified as CWE‑354, arises from insufficient validation of message integrity in the S/MIME decryption functionality of Cisco Secure Email. An unauthenticated, remote attacker can exploit this flaw via a man‑in‑the‑middle approach to intercept and modify traffic between email gateways. Successful exploitation permits the attacker to recover plaintext from encrypted email communications, leading to a confidentiality breach.
Affected Systems
Cisco Secure Email is affected. No specific version information is provided, so all relevant deployments of Cisco Secure Email should be reviewed for the vulnerability.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The lack of an EPSS score suggests limited publicly known exploitation, but the attack requires an active man‑in‑the‑middle position and no authentication, making it potentially realistic in compromised network segments. The risk remains significant for confidentiality if the attacker can position themselves between email gateways.
OpenCVE Enrichment