Impact
The vulnerability is caused by a failure to properly validate quantity values supplied in user input on Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. The flaw is classified as an input‑validation weakness (CWE‑1284) and could allow an attacker to send or influence quantity parameters that do not conform to expected ranges, potentially causing the software to behave unexpectedly or fail to process requests correctly.
Affected Systems
The affected products are Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. No specific version information is provided in the advisory; all deployed instances of these products are potentially impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity level. The EPSS score of < 1% means the likelihood of exploitation is very low but not zero. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through web or service interfaces where quantity parameters are accepted; this inference is drawn from the description that improperly validated quantity values can be supplied by users.
OpenCVE Enrichment