CVE-2015-0624: Cisco Content Security Management Appliance

Medium severity, CVSS 4.3. EPSS: 2.2% chance of exploitation in the next 30 days.

The web framework in Cisco AsyncOS on Email Security Appliance (ESA), Content Security Management Appliance (SMA), and Web Security Appliance (WSA) devices allows remote attackers to trigger redirects via a crafted HTTP header, aka Bug IDs CSCur44412, CSCur44415, CSCur89630, CSCur89636, CSCur89633, and CSCur89639.

Affected products

  • Cisco Content Security Management Appliance: affected versions not specified
  • Cisco Email Security Appliance Firmware: affected versions not specified
  • Cisco Web Security Appliance: affected versions not specified

Published 2015-02-21. Last modified 2026-06-17.