CVE-2016-9202: Cisco Email Security Appliance

Medium severity, CVSS 6.1. EPSS: 1.3% chance of exploitation in the next 30 days.

A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) Switches could allow an unauthenticated, remote attacker to conduct a persistent cross-site scripting (XSS) attack against a user of the affected interface on an affected device. More Information: CSCvb37346. Known Affected Releases: 9.1.1-036 9.7.1-066.

Affected products

  • Cisco Email Security Appliance: version 9.1.1-036 only; version 9.1.2-023 only; version 9.1.2-028 only; version 9.1.2-036 only; version 9.4.0 only; version 9.4.4-000 only; …

Published 2016-12-14. Last modified 2026-06-17.