Impact
Multiple vulnerabilities in Cisco Secure Email’s S/MIME decryption allow an unauthenticated attacker to recover plaintext from encrypted messages. The weaknesses stem from insufficient validation of message integrity, enabling a man‑in‑the‑middle to modify traffic and force the system into decrypting tampered payloads. The result is a compromise of confidentiality, exposing the contents of supposedly protected communications.
Affected Systems
Affected systems include Cisco Secure Email. Version details are not specified; the vulnerability impacts the S/MIME decryption component used by the product.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. EPSS is not available and the vulnerability is not listed in CISA KEV, so current exploitation likelihood is uncertain. The described attack requires a network position that permits traffic interception, such as a compromised email gateway or insecure network segment, and relies on the attacker’s ability to alter encrypted messages before decryption occurs. This is an identified weakness in cryptographic protocol implementation per CWE-345.
OpenCVE Enrichment