CVE-2022-20634 (CNNVD-202201-966)
中文标题:
Cisco Enterprise Chat and Email 输入验证错误漏洞
英文标题:
Cisco Enterprise Chat and Email Open Redirect Vulnerability
漏洞描述
中文描述:
Cisco Enterprise Chat and Email(CEC)是美国思科(Cisco)公司的一套企业聊天和电子邮件解决方案。该产品主要为其它Cisco解决方案提供电子邮件、聊天和Web回调功能等。 Cisco Enterprise Chat and Email存在输入验证错误漏洞,该漏洞源于 Cisco ECE 基于 Web 的管理界面中的一个漏洞可能允许未经身份验证的远程攻击者将用户重定向到不需要的网页。此漏洞是由于对发送到 受影响的系统。 攻击者可以通过诱使界面用户单击精心制作的链接来利用此漏洞。 成功的利用可能允许攻击者使界面将用户重定向到特定的恶意 URL。 这种类型的漏洞称为开放重定向,用于网络钓鱼攻击,使用户在不知不觉中访问恶意网站。
英文描述:
A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. This vulnerability is due to improper input validation of the URL parameters in an HTTP request that is sent to an affected system. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to cause the interface to redirect the user to a specific, malicious URL. This type of vulnerability is known as an open redirect and is used in phishing attacks that get users to unknowingly visit malicious sites.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco | Cisco Enterprise Chat and Email | 11.6(1)_ES3 | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:11.6(1)_es3:*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 11.6(1)_ES4 | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:11.6(1)_es4:*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 12.0(1)_ES6 | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:12.0(1)_es6:*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 11.6(1)_ES8 | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:11.6(1)_es8:*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 12.0(1)_ES5a | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:12.0(1)_es5a:*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 11.6(1)_ES9 | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:11.6(1)_es9:*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 12.0(1)_ES6_ET1 | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:12.0(1)_es6_et1:*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 11.6(1)_ES6 | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:11.6(1)_es6:*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 11.6(1)_ES5 | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:11.6(1)_es5:*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 12.5(1)_ET1 | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:12.5(1)_et1:*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 12.5(1) | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:12.5(1):*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 12.5(1)_ES3_ET1 | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:12.5(1)_es3_et1:*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 12.0(1)_ES3 | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:12.0(1)_es3:*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 11.6(1)_ES11 | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:11.6(1)_es11:*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 12.0(1)_ES4 | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:12.0(1)_es4:*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 12.0(1)_ES5 | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:12.0(1)_es5:*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 11.6(1)_ES2 | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:11.6(1)_es2:*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 11.6(1)_ES9a | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:11.6(1)_es9a:*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 11.6(1)_ES10 | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:11.6(1)_es10:*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 12.0(1)_ES1 | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:12.0(1)_es1:*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 12.0(1) | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:12.0(1):*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 12.5(1)_ES3 | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:12.5(1)_es3:*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 12.6(1) | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:12.6(1):*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 11.5(1) | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:11.5(1):*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 12.0(1)_ES2 | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:12.0(1)_es2:*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 11.6(1)_ES7 | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:11.6(1)_es7:*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 12.5(1)_ES2 | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:12.5(1)_es2:*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 12.6(1)_ET1 | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:12.6(1)_et1:*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 11.6(1) | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:11.6(1):*:*:*:*:*:*:*
|
| Cisco | Cisco Enterprise Chat and Email | 12.5(1)_ES1 | - | - |
cpe:2.3:a:cisco:cisco_enterprise_chat_and_email:12.5(1)_es1:*:*:*:*:*:*:*
|
| cisco | enterprise_chat_and_email | * | - | - |
cpe:2.3:a:cisco:enterprise_chat_and_email:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
3.1 (cna)
MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2022-20634 |
2025-11-11 15:21:15 | 2025-11-11 07:37:15 |
| NVD | nvd_CVE-2022-20634 |
2025-11-11 14:58:35 | 2025-11-11 07:45:31 |
| CNNVD | cnnvd_CNNVD-202201-966 |
2025-11-11 15:10:48 | 2025-11-11 07:57:07 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 输入验证错误
- cnnvd_id: 未提取 -> CNNVD-202201-966
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 30 -> 31
- data_sources: ['cve'] -> ['cve', 'nvd']