Impact
The vulnerability is a path traversal flaw that allows an attacker to read or possibly write arbitrary files on the Cisco Secure Email or Secure Email and Web Manager. This weakness can expose sensitive configuration information or enable modification of files that may compromise credentials or other confidential data, and could be leveraged to alter system behavior. The flaw aligns with CWE-23, indicating a failure to properly validate path components, which can compromise confidentiality and integrity but is not explicitly described as enabling remote code execution.
Affected Systems
The affected products are Cisco Secure Email and Cisco Secure Email and Web Manager. No specific version range is documented, implying that all releases lacking the hardening patch are vulnerable.
Risk and Exploitability
The CVSS score of 9.8 categorizes the issue as critical. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, yet the severity and potential for damaging file access warrant urgent attention. Based on the description, it is inferred that attackers would likely need remote access to the web‑based administrative interface or API, and may require authenticated credentials to traverse directories, so misconfigured or exposed management ports increase the risk.
OpenCVE Enrichment