Impact
The CVE describes a flaw that falls under improper access control (CWE‑284). The advisory notes that this issue relates to improper access control within the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, but does not provide specific details about how the flaw might be exploited or the precise effects on confidentiality, integrity, or availability.
Affected Systems
The affected systems are Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. The advisory notes that the vulnerabilities were discovered internally and have been patched in recent hardening releases. No specific firmware or software versions are listed, so administrators should consult Cisco’s security knowledge base to determine applicability to their deployments.
Risk and Exploitability
The advisory does not detail an exact exploitation path. The CVSS score of 9.8 indicates a critical severity level. The EPSS score of less than 1% indicates a low but non-zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment