CVE-2023-20057
A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. This vulnerability is due to improper processing of URLs. An attacker could exploit this vulnerability by crafting a URL in a particular way. A successful exploit could allow the attacker to bypass the URL reputation filters that are configured for an affected device, which could allow malicious URLs to pass through the device.
Scoring
- Severity
- NONE
- CVSS base score
- 0
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N
- EPSS probability
- 0.97%
- CWE
- CWE-792
- Published
- 2023-01-19
- Last modified
- 2026-03-13
Affected products
- Cisco Cisco Email Security Appliance (ESA)
Weakness type
Related vulnerabilities
- CVE-2025-12758 — Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or...
- CVE-2025-47779 — Using malformed From header can forge identity with ";" or NULL in name portion
- CVE-2023-25608 — An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the...
- CVE-2022-22297 — An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the...